{"id":23772,"date":"2026-09-28T09:53:56","date_gmt":"2026-09-28T09:53:56","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23772"},"modified":"2026-09-28T09:53:56","modified_gmt":"2026-09-28T09:53:56","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p><b>Question 61.<\/b><\/p>\n<p><b>A SOC analyst observes repeated failed authentication attempts against a privileged account from several internal hosts, followed by one successful login. What should the analyst investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Possible credential compromise and lateral movement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer configuration errors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disk fragmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP lease expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated authentication failures from multiple internal systems followed by a successful login to a privileged account can indicate credential compromise, password spraying, or lateral movement. The analyst should determine which systems generated the attempts, whether the successful login is consistent with the account owner&#8217;s normal behavior, and what activity followed authentication. Domain controller logs, EDR telemetry, VPN records, and identity-provider data can provide valuable context. Because the account is privileged, the event should generally receive higher priority than similar activity involving a low-impact account. Printer configuration and disk fragmentation are unrelated. Analysts should also check whether the source systems themselves are compromised and whether the account authenticated to additional hosts afterward.<\/span><\/p>\n<p><b>Question 62.<\/b><\/p>\n<p><b>Which information would be most useful for determining whether authentication activity represents normal administrator behavior or malicious lateral movement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitor model information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Historical user and host behavior baselines<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Laptop battery health<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer toner levels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Historical behavior baselines help analysts understand what is normal for a specific account and system. An administrator who routinely authenticates to dozens of servers may generate activity that would be highly suspicious for a standard office user. Baselines can include commonly accessed systems, normal working hours, source devices, authentication methods, network locations, and typical administrative tools. They should not be treated as absolute truth because legitimate behavior can change, but they provide useful investigative context. Hardware inventory and printer information do not explain authentication patterns. Analysts should combine baseline deviations with asset criticality, privilege level, authentication telemetry, process activity, and threat intelligence before determining whether lateral movement is occurring.<\/span><\/p>\n<p><b>Question 63.<\/b><\/p>\n<p><b>A security analyst identifies a suspicious domain in DNS logs. Which pivot would provide the most useful next step for scoping the incident?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search for all internal hosts that queried or connected to the domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace every DNS server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the DNS logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all name resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Once a suspicious domain is identified, searching across historical DNS, proxy, firewall, and endpoint telemetry for all hosts that interacted with it helps establish incident scope. The analyst can determine whether the activity is limited to one endpoint or appears across many systems. Additional pivots can include associated IP addresses, downloaded files, process names, user accounts, and timestamps. Replacing DNS infrastructure or disabling name resolution would be disruptive and would not necessarily address the underlying compromise. Deleting logs would destroy valuable evidence. Effective investigations often begin with one indicator and expand through related artifacts until analysts understand the affected systems, users, and attack sequence.<\/span><\/p>\n<p><b>Question 64.<\/b><\/p>\n<p><b>Which network behavior is most consistent with data exfiltration from a compromised endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Normal ARP requests to the default gateway<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A routine DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Standard NTP synchronization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> An unusual large outbound transfer to an external destination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A large outbound transfer to an unusual external destination can be an indicator of data exfiltration, particularly when the destination is rare, newly registered, or associated with malicious infrastructure. Analysts should review transfer volume, protocol, destination reputation, user context, endpoint process information, data classification, and whether similar communication has occurred previously. A large transfer alone does not prove compromise because legitimate cloud backup, file sharing, software distribution, or business workflows can generate substantial outbound traffic. ARP, DHCP, and NTP normally involve smaller, predictable infrastructure-related exchanges. Correlating network telemetry with endpoint and user activity helps determine whether the transfer represents legitimate business use or unauthorized data movement.<\/span><\/p>\n<p><b>Question 65.<\/b><\/p>\n<p><b>Which technique would help an analyst identify potentially encoded command-and-control traffic hidden within DNS queries?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze query length, entropy, frequency, and subdomain patterns<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Check monitor resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review printer queues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replace the endpoint hard drive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling often produces unusual query characteristics such as very long subdomains, high-entropy strings, repetitive request patterns, or unusually high query volumes to a small set of domains. Analysts can compare these characteristics with normal DNS behavior to identify potential covert communication. The responsible process on the endpoint should also be identified, and the domain&#8217;s reputation, registration age, and passive DNS history should be reviewed. Legitimate content-delivery, telemetry, or security products may also generate unusual DNS names, so statistical anomalies should be validated with context. Display settings, printer queues, and hard-drive replacement have no direct relevance to DNS tunneling analysis.<\/span><\/p>\n<p><b>Question 66.<\/b><\/p>\n<p><b>A security team wants to reduce alert fatigue caused by a SIEM rule that frequently triggers on legitimate administrative activity. What should be done?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all security logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Tune the rule using contextual conditions while preserving meaningful detection coverage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore every future alert from the rule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete historical events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection tuning should reduce unnecessary false positives without creating a significant detection gap. Analysts can refine the rule by incorporating approved administrator accounts, known management systems, normal execution paths, expected time windows, command-line characteristics, or other contextual factors. The goal is not simply to reduce the number of alerts but to improve signal quality. Disabling logging or ignoring every alert would remove useful visibility, while deleting historical data prevents retrospective analysis. After tuning, the rule should be tested against known malicious patterns to verify that important behavior is still detected. Detection engineering is an iterative process informed by incidents, threat hunting, baselines, and analyst feedback.<\/span><\/p>\n<p><b>Question 67.<\/b><\/p>\n<p><b>Which term describes an alert that correctly identifies actual malicious activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> True positive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> False positive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> True negative<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> False negative<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A true positive occurs when a detection mechanism generates an alert and investigation confirms that the underlying activity is genuinely malicious. For example, an endpoint alert that identifies actual credential dumping would be a true positive. A false positive is an alert for legitimate activity, while a false negative occurs when malicious activity happens but is not detected. A true negative represents benign activity that correctly produces no alert. Tracking these classifications helps security teams measure detection quality, tune rules, and identify gaps. True positives should also be used as opportunities to hunt for similar behavior elsewhere and to assess whether containment, response, and escalation procedures worked effectively.<\/span><\/p>\n<p><b>Question 68.<\/b><\/p>\n<p><b>Which term describes malicious activity that occurs without generating the expected security alert?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> True positive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> True negative<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> False positive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> False negative<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false negative occurs when malicious behavior takes place but the security control fails to generate an alert. False negatives are particularly dangerous because they can allow an attacker to remain undetected while defenders believe monitoring is functioning correctly. They may result from missing telemetry, poor parsing, overly narrow detection logic, disabled sensors, or new attacker techniques. True positives correctly identify malicious activity, false positives alert on legitimate behavior, and true negatives correctly remain silent for benign activity. Post-incident reviews, threat hunting, adversary simulation, and retrospective searches can reveal false negatives and help security teams improve detection coverage.<\/span><\/p>\n<p><b>Question 69.<\/b><\/p>\n<p><b>An analyst finds that a user clicked a phishing link and shortly afterward an Office application spawned PowerShell. What should the analyst investigate next?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PowerShell command-line activity and subsequent network connections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The monitor&#8217;s refresh rate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer driver versions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> UPS battery condition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Office applications spawning PowerShell shortly after a phishing event can indicate malicious code execution. The analyst should inspect the complete PowerShell command line, script-block logging when available, parent-child process relationships, downloaded files, persistence actions, and outbound connections. The investigation should also determine whether credentials were accessed or whether additional hosts were targeted. Endpoint telemetry, email security logs, proxy records, DNS data, and authentication events can help reconstruct the attack chain. Hardware display and power information are not relevant. The analyst should also search the environment for similar process chains to determine whether other users received or executed the same malicious content.<\/span><\/p>\n<p><b>Question 70.<\/b><\/p>\n<p><b>Which source is most useful for determining how a suspicious attachment entered the organization and which recipients received it?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Email security gateway logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP cache entries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Switch port counters<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Email security gateway logs can provide message sender information, recipients, timestamps, subject lines, attachment metadata, message IDs, URLs, and delivery actions. This makes them highly valuable for phishing investigations. Analysts can determine whether the message reached one or many users and then correlate recipient information with endpoint telemetry to identify who opened the attachment or clicked a link. DHCP and ARP data provide network information but do not describe email delivery. Switch counters likewise cannot identify message recipients. Email investigation should also include header analysis, sender reputation, domain intelligence, and related messages so the SOC can quickly scope and contain a campaign.<\/span><\/p>\n<p><b>Question 71.<\/b><\/p>\n<p><b>Which activity most directly supports identifying additional hosts affected by a newly discovered malicious file hash?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retrospective endpoint search<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hardware replacement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Password expiration review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A retrospective endpoint search allows analysts to query historical telemetry for a newly identified malicious hash. This can reveal systems that downloaded, stored, or executed the file before the indicator was known to be malicious. Analysts should not stop at exact hash matching because attackers can change file contents to generate different hashes. Related filenames, paths, certificates, parent processes, domains, and behaviors should also be examined. Retrospective searches depend on adequate telemetry retention, so organizations should maintain data long enough to support investigations. Hardware replacement and printer inventory do not help determine whether the malicious file existed elsewhere in the environment.<\/span><\/p>\n<p><b>Question 72.<\/b><\/p>\n<p><b>Which security practice helps ensure that forensic evidence can be shown to have remained unchanged after collection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rename the evidence file<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Move it repeatedly between folders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Calculate a cryptographic hash and verify it later<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change the file extension<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash provides a content-based value that can be recalculated later and compared with the original. Matching values provide evidence that the forensic image or file has not changed. This supports forensic integrity and complements chain-of-custody documentation. Renaming, moving, or changing the extension does not prove integrity and may change metadata. Analysts should preserve original evidence when possible and perform analysis on validated copies. The acquisition process, tools, timestamps, storage location, and personnel involved should also be documented. If the hash unexpectedly changes, the difference must be investigated because the evidence may have been modified or corrupted.<\/span><\/p>\n<p><b>Question 73.<\/b><\/p>\n<p><b>Why is chain of custody important during a security investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It documents who handled evidence and when<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It increases processor performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically removes malware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Chain of custody documents the collection, transfer, storage, analysis, and access history of evidence. It helps show that evidence was handled consistently and was not improperly modified, lost, or substituted. This becomes especially important when an investigation may support legal, regulatory, disciplinary, or law-enforcement action. A chain-of-custody record may include evidence identifiers, dates and times, signatures, storage details, and every transfer between individuals. It does not improve system performance, remove malware, or replace cryptographic protection. Evidence handling should also include integrity verification, access controls, and approved forensic procedures so investigative findings remain defensible and reproducible.<\/span><\/p>\n<p><b>Question 74.<\/b><\/p>\n<p><b>Which data should generally receive high priority for collection because it may disappear when a compromised computer is powered off?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printed asset tags<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Volatile memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Purchase invoices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Rack diagrams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Volatile memory can contain active processes, network connections, injected code, command history, encryption material, credentials, and other artifacts that may disappear when power is removed. Therefore, memory acquisition may be prioritized when volatile evidence is relevant and collection is permitted by organizational procedures. The exact order of volatility depends on the investigation and should be balanced against containment needs. Printed records and physical diagrams are persistent and do not disappear when the system is shut down. Memory acquisition should be performed using approved forensic methods, with collection actions documented and resulting evidence protected through hashes and chain-of-custody procedures where appropriate.<\/span><\/p>\n<p><b>Question 75.<\/b><\/p>\n<p><b>An attacker creates a new service that launches malicious code every time Windows starts. Which security objective does this behavior most directly support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating a service that automatically launches malicious code at startup is a persistence technique because it allows the attacker to regain execution after a reboot. Persistence mechanisms can include services, scheduled tasks, startup items, registry entries, modified authentication components, or newly created accounts. Discovery focuses on learning about the environment, Exfiltration involves stealing data, and Impact concerns disruption or destruction. During eradication, analysts must remove persistence mechanisms as well as visible malware files. Otherwise, the malicious payload may simply return after restart. The SOC should also hunt for similar service creation on other systems to determine whether the attacker established persistence more broadly.<\/span><\/p>\n<p><b>Question 76.<\/b><\/p>\n<p><b>Which action best represents containment during incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Writing a lessons-learned report<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Updating annual training material<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Purchasing replacement hardware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Isolating a compromised endpoint from the network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment aims to limit the scope, spread, and impact of an active compromise. Isolating an infected endpoint can prevent additional command-and-control communication, lateral movement, malware propagation, or data exfiltration while analysts continue investigating. Containment methods may include EDR network isolation, firewall blocks, account disabling, segmentation, or physical disconnection depending on the incident. Lessons learned occurs after the incident, while training and procurement are broader operational activities. Containment decisions should consider evidence preservation and business impact. In some cases, analysts may first need to capture volatile evidence if doing so does not create unacceptable risk.<\/span><\/p>\n<p><b>Question 77.<\/b><\/p>\n<p><b>Which activity belongs primarily to the eradication phase of incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing malware and persistence mechanisms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establishing the SOC staffing plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Creating asset purchase orders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Writing employee vacation schedules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication focuses on removing the root causes and malicious components associated with an incident. This can include deleting malware, removing scheduled tasks or services used for persistence, patching exploited vulnerabilities, closing unauthorized accounts, and resetting compromised credentials. Containment limits the immediate spread, while recovery restores normal operation after the threat has been removed. Simply deleting one malicious executable may be insufficient if persistence or stolen credentials remain. Analysts should understand the attack path and confirm that all known footholds have been addressed. Depending on incident severity, rebuilding systems from trusted images may provide greater confidence than attempting to clean them manually.<\/span><\/p>\n<p><b>Question 78.<\/b><\/p>\n<p><b>Which action belongs primarily to the recovery phase of incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Developing the incident-response plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Restoring systems to production and monitoring for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Collecting threat intelligence before an incident<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Creating employee badges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery focuses on safely returning systems and services to normal operation after the threat has been contained and eradicated. Activities can include restoring data, rebuilding endpoints, validating security controls, reconnecting systems to the network, and closely monitoring for signs that the attacker has returned. Recovery should not begin until analysts have reasonable confidence that persistence and root causes have been addressed. Preparation activities such as creating response plans occur before incidents, while threat intelligence collection can support several phases. Post-recovery monitoring is essential because recurrence may indicate incomplete eradication, compromised credentials, or an unrecognized access path.<\/span><\/p>\n<p><b>Question 79.<\/b><\/p>\n<p><b>A post-incident review finds that a compromised endpoint had no process command-line logging, preventing analysts from understanding the attacker&#8217;s commands. What improvement should be prioritized?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enable appropriate command-line and endpoint telemetry collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove all endpoint sensors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reduce log retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable script logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The missing command-line telemetry represents a visibility gap that directly limited the investigation. Enabling appropriate endpoint, process, PowerShell, and command-line logging can provide richer evidence for future incidents and improve detection engineering. The organization should balance logging depth with storage, privacy, and performance requirements, but reducing or disabling telemetry would worsen the problem. The post-incident review should document the gap, assign ownership for remediation, test the new logging configuration, and ensure the data reaches the SIEM or EDR platform correctly. Lessons learned are most valuable when they produce concrete, measurable improvements rather than remaining only as written observations.<\/span><\/p>\n<p><b>Question 80.<\/b><\/p>\n<p><b>After an incident is fully resolved, which action provides the greatest long-term defensive value?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the investigation records immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable the detections that generated alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Document lessons learned and improve detections, procedures, and controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore the incident because systems are operational again<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A structured lessons-learned process converts an incident into improvements for future defense. The team should review what happened, how quickly the attack was identified, which controls worked, where visibility or process gaps existed, and how containment and recovery were handled. Useful outcomes can include new detection rules, updated threat-hunting queries, improved logging, stronger access controls, revised incident-response playbooks, better automation, or additional training. Deleting records or ignoring the event wastes valuable knowledge, while disabling detections could create new gaps. Incident response should therefore be treated as a continuous improvement cycle in which each confirmed event strengthens prevention, detection, investigation, and response capabilities.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps Question 61. A SOC analyst observes repeated failed authentication attempts against a privileged account from several internal hosts, followed by one successful login. What should the analyst investigate first? Possible credential compromise and lateral movement 2. Printer configuration errors 3. Disk fragmentation 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23772"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23772"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23772\/revisions"}],"predecessor-version":[{"id":23773,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23772\/revisions\/23773"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23772"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}