{"id":23774,"date":"2026-09-28T09:54:14","date_gmt":"2026-09-28T09:54:14","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23774"},"modified":"2026-09-28T09:54:14","modified_gmt":"2026-09-28T09:54:14","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 81.<\/b><\/p>\n<p><b>A security analyst observes a user account successfully authenticating from an internal workstation and then accessing several servers the user has never contacted before. Which activity should the analyst investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Potential lateral movement using compromised credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Routine DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Normal DNS recursion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Scheduled endpoint inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sudden change in authentication behavior, especially when an account begins accessing multiple unfamiliar systems, can indicate lateral movement with compromised credentials. The analyst should review the originating host, authentication type, timestamps, destination systems, privilege level, and any processes launched after each login. EDR telemetry may reveal remote administration tools, PowerShell, service creation, or other activity associated with lateral movement. Historical baselines are also valuable because some administrators legitimately access many systems while ordinary users usually do not. DHCP and DNS activity would not directly explain the unusual authentication pattern. If compromise is confirmed, containment may include isolating the originating endpoint, restricting the affected account, and searching for the same behavior across additional systems.<\/span><\/p>\n<p><b>Question 82.<\/b><\/p>\n<p><b>Which log source is most valuable when investigating whether a compromised account was used to authenticate to multiple Windows systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows authentication and domain controller security logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Monitor inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> UPS logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows authentication events and domain controller security logs can provide important information about successful and failed logins, account names, source systems, destination systems, logon types, and authentication protocols. These events are central to investigating credential abuse and lateral movement. Analysts should correlate authentication logs with endpoint telemetry to identify what happened immediately after each login, because successful authentication alone does not prove malicious activity. For example, process creation, remote service execution, PowerShell, or unusual file access may strengthen the case. Printer, display, and UPS logs generally do not provide useful identity context. Accurate timestamps are especially important because the analyst may need to reconstruct the sequence of logins across many hosts.<\/span><\/p>\n<p><b>Question 83.<\/b><\/p>\n<p><b>A user account generates hundreds of login failures against a single server using many different passwords. Which attack pattern is most consistent with this behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password spraying<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Brute-force password attack<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force password attack typically involves attempting many different passwords against one account or one target until a valid credential is discovered. Password spraying usually takes the opposite approach by trying one or a few commonly used passwords against many different accounts to reduce the chance of triggering per-account lockout thresholds. DNS tunneling and ARP poisoning are unrelated to password guessing. The analyst should examine the source IP address, authentication method, account lockout events, timing, and whether any attempt eventually succeeded. If a login was successful, subsequent account activity becomes particularly important. Defensive controls can include MFA, appropriate lockout policies, rate limiting, monitoring, and strong password practices.<\/span><\/p>\n<p><b>Question 84.<\/b><\/p>\n<p><b>An analyst observes one commonly used password being attempted against hundreds of different accounts. Which attack should be suspected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Credential stuffing only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ARP spoofing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> SQL injection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Password spraying<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password spraying involves testing one or a small number of common passwords across many accounts. This strategy can help attackers avoid triggering traditional account lockout controls that focus on repeated failures against a single user. Analysts should search identity logs for the same source IP, repeated failure patterns, targeted usernames, and any successful authentication that follows. They should also review MFA events and determine whether the source is associated with known malicious infrastructure. Credential stuffing instead typically uses previously stolen username-and-password pairs. If a password-spraying attempt succeeds, incident scope should expand to the affected account, the source device, and any resources accessed after authentication.<\/span><\/p>\n<p><b>Question 85.<\/b><\/p>\n<p><b>A SOC receives a threat-intelligence report containing a malicious domain first observed yesterday. What is the most useful initial action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search historical DNS, proxy, firewall, and endpoint data for the domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reimage every endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all DNS caches across the enterprise without investigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable internet access permanently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A retrospective search across historical telemetry can reveal whether internal systems interacted with the malicious domain before the organization knew it was suspicious. DNS data can show which hosts resolved it, proxy logs can identify web requests, firewall records can show network connections, and endpoint telemetry can reveal which processes generated those connections. This approach helps determine incident scope while preserving evidence. Reimaging every endpoint would be unnecessarily disruptive, and broad changes without confirming exposure may obscure useful investigative context. Analysts should also review the age and confidence of the intelligence because domains can change ownership or purpose. If affected systems are identified, the investigation can pivot to related files, processes, users, IP addresses, and persistence mechanisms.<\/span><\/p>\n<p><b>Question 86.<\/b><\/p>\n<p><b>Which characteristic of threat intelligence is most important before automatically blocking an IP address across the enterprise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The indicator contains only numbers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Confidence, freshness, and context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The source uses a colorful dashboard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The IP address responds to ping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before automatically blocking infrastructure, the SOC should consider the confidence of the source, how recently malicious activity was observed, and the context associated with the indicator. IP addresses can be reassigned, shared by many services, or belong to cloud infrastructure hosting both legitimate and malicious workloads. A stale or low-confidence indicator can therefore create false positives and disrupt business traffic. Ping responsiveness does not determine maliciousness, and presentation quality has no bearing on intelligence reliability. Mature security programs assign confidence, severity, timestamps, and source information to indicators and may use different response actions based on those attributes. High-confidence active command-and-control infrastructure may justify blocking, while lower-confidence data may be more appropriate for alert enrichment.<\/span><\/p>\n<p><b>Question 87.<\/b><\/p>\n<p><b>A threat hunter is looking for abnormal parent-child process relationships such as <\/b><b>winword.exe<\/b><b> spawning <\/b><b>powershell.exe<\/b><b>. What type of detection approach is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Behavioral detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File-hash-only detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hardware inventory detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical access detection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral detection focuses on what processes and users are doing rather than relying solely on static indicators such as hashes or IP addresses. An Office application spawning PowerShell can be suspicious because document-based attacks frequently abuse scripting interpreters to execute additional payloads. However, the relationship is not automatically malicious, so analysts should examine the document source, command-line arguments, PowerShell logging, child processes, and network connections. Behavioral detections can remain useful when attackers modify malware files or infrastructure because the underlying techniques may remain similar. Static indicators still provide value, but combining them with process behavior creates stronger and more durable detection coverage.<\/span><\/p>\n<p><b>Question 88.<\/b><\/p>\n<p><b>A security rule alerts every time PowerShell runs, creating thousands of benign alerts. Which tuning approach best preserves useful detection coverage?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable PowerShell telemetry completely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore every PowerShell event<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Alert only when PowerShell executes during business hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Add suspicious context such as encoded commands, unusual parents, or network behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PowerShell is widely used for legitimate administration, so alerting on every execution creates excessive noise. A stronger rule looks for contextual factors associated with malicious use, such as encoded commands, execution from unusual parent processes, hidden windows, downloads, suspicious script blocks, unusual users, or unexpected outbound connections. This improves precision without removing visibility entirely. Disabling PowerShell telemetry or ignoring all events would create a major detection gap. Restricting alerts based only on time is also weak because attackers can operate during normal business hours. Detection tuning should be tested against known malicious examples to ensure that reducing false positives does not create unacceptable false negatives.<\/span><\/p>\n<p><b>Question 89.<\/b><\/p>\n<p><b>Which situation represents a false positive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A legitimate administrative script triggers a malware-style PowerShell alert<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Malware runs but no alert is generated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Malware runs and the SOC correctly alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Benign activity occurs and no alert is generated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false positive occurs when a security control generates an alert for activity that investigation determines is legitimate. In this example, the detection mechanism correctly observed suspicious-looking PowerShell behavior but misclassified approved administrative activity as malicious. A false negative occurs when malware runs without generating an alert. A true positive occurs when malicious behavior is correctly detected, while a true negative is benign activity that correctly produces no alert. SOC teams should track false-positive patterns because excessive noise can create analyst fatigue and slow response to genuine threats. However, tuning must be performed carefully so that legitimate exceptions do not become broad exclusions that attackers can exploit.<\/span><\/p>\n<p><b>Question 90.<\/b><\/p>\n<p><b>Which situation represents a false negative?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A harmless administrative command triggers an alert<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Malicious credential dumping occurs but no alert is generated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A malicious file triggers a correct endpoint alert<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Legitimate activity produces no alert<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false negative occurs when malicious activity happens but the detection system fails to identify it. In this case, credential dumping took place without an alert, leaving the organization unaware of a potentially serious compromise. False negatives can result from missing telemetry, disabled sensors, poor parsing, overly narrow detection rules, or attacker techniques that have not yet been covered. A post-incident review should determine why the activity was missed and what telemetry or detection logic is needed to close the gap. Threat hunting, adversary simulation, and retrospective searches can also reveal similar undetected activity. False negatives are especially dangerous because they create a false sense of security.<\/span><\/p>\n<p><b>Question 91.<\/b><\/p>\n<p><b>A host sends a small HTTPS request to the same external destination approximately every sixty seconds. What additional evidence would most help distinguish malware beaconing from a legitimate management agent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The process responsible for each network connection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The monitor&#8217;s refresh rate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The user&#8217;s keyboard layout<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The workstation&#8217;s asset color<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process attribution is critical when evaluating periodic network activity. If the connection originates from a known and properly signed management agent communicating with its expected vendor infrastructure, the behavior may be legitimate. If it comes from an unsigned executable in a temporary directory or from an unusual script interpreter, the same traffic pattern becomes far more suspicious. The analyst should also consider destination reputation, TLS certificate details, timing regularity, data volume, domain age, and whether similar traffic appears on other managed systems. Hardware display characteristics provide no meaningful network context. Correlating endpoint and network telemetry is one of the most effective methods for separating malicious beaconing from legitimate automated communications.<\/span><\/p>\n<p><b>Question 92.<\/b><\/p>\n<p><b>Which telemetry would be most useful for identifying the internal systems that resolved a suspicious command-and-control domain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asset purchase records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS query logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer maintenance logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Video surveillance records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS query logs can show which clients requested resolution for a particular domain and when those queries occurred. This makes them valuable for incident scoping after a malicious or command-and-control domain is discovered. Analysts can search for all clients that queried the domain, then pivot into endpoint and network telemetry for each host. DNS activity does not necessarily prove that a successful connection occurred, so firewall or proxy data should be used to confirm actual communication when possible. Analysts should also review DNS response data, caching behavior, and timestamps. Purchase, printer, and physical-security records do not provide the required name-resolution visibility.<\/span><\/p>\n<p><b>Question 93.<\/b><\/p>\n<p><b>A SOC analyst wants to determine whether sensitive information was transmitted through DNS. Which network pattern would be most suspicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Occasional requests for common corporate domains<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Standard reverse DNS lookups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Repeated long, high-entropy subdomain queries carrying varying encoded data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Normal DNS server health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling can encode information into subdomains or DNS responses, producing unusually long, high-entropy labels and repeated requests to a small set of domains. When the encoded portion changes frequently, it may represent data being transferred through DNS. Analysts should evaluate query length, frequency, entropy, record types, destination domain reputation, and endpoint process information. Legitimate cloud and security services can also produce complex DNS names, so the pattern must be validated before it is considered malicious. If tunneling is suspected, the analyst should identify the responsible process, examine the domain&#8217;s history, and determine whether the endpoint contains other signs of compromise.<\/span><\/p>\n<p><b>Question 94.<\/b><\/p>\n<p><b>Which information is most important when reconstructing a multi-system incident timeline from different log sources?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Screen resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Consistent timestamps and time-zone awareness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Monitor serial numbers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Laptop battery capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accurate timestamps are essential for correlating events from endpoints, firewalls, identity platforms, email systems, cloud services, and other sources. Systems should ideally use synchronized time services, and analysts need to know whether each platform records timestamps in UTC or local time. Clock drift can make actions appear in the wrong order and lead to incorrect conclusions about cause and effect. The analyst should normalize time values before creating a timeline and document any known time discrepancies. Hardware display and battery information do not contribute to chronological reconstruction. Reliable timestamps are particularly important when tracing phishing delivery, execution, credential theft, lateral movement, and exfiltration across multiple systems.<\/span><\/p>\n<p><b>Question 95.<\/b><\/p>\n<p><b>An analyst is preparing to collect forensic evidence from an active compromised endpoint. Which evidence is generally considered the most volatile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> System memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Files stored on an offline backup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printed network diagrams<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Archived asset records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">System memory is highly volatile because its contents can disappear when the host loses power or is restarted. RAM may contain active processes, injected code, network connections, decrypted data, authentication artifacts, encryption keys, and other information that is difficult or impossible to recover later. For this reason, memory acquisition may be prioritized when forensic procedures and incident conditions permit. Stored files and printed records are much less volatile. Analysts must still balance evidence collection with containment because delaying isolation could allow additional malicious activity. The collection method, tool, operator, timestamp, and resulting hash should be documented when forensic integrity is important.<\/span><\/p>\n<p><b>Question 96.<\/b><\/p>\n<p><b>Which control is most directly used to demonstrate that a forensic image has not changed since it was collected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing the filename<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Compressing the image<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Storing it in a new directory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Verifying a cryptographic hash<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash produces a deterministic value based on the evidence contents. By calculating a hash at acquisition and comparing it with a later value, investigators can demonstrate that the forensic image has remained unchanged. This supports evidence integrity and complements chain-of-custody documentation. Renaming, moving, or compressing evidence does not provide the same assurance. Analysts should generally preserve original evidence and conduct analysis on verified working copies. If a hash value differs unexpectedly, the discrepancy should be investigated and documented because the evidence may have changed or become corrupted. Strong evidence handling is especially important when findings may be used for regulatory, disciplinary, or legal purposes.<\/span><\/p>\n<p><b>Question 97.<\/b><\/p>\n<p><b>A compromised endpoint contains a scheduled task, a newly created service, and a registry startup entry, all launching the same payload. Which adversary goal do these artifacts primarily support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scheduled tasks, services, and startup registry entries are common persistence mechanisms because they allow malicious code to execute again after reboot, logon, or interruption. Multiple persistence techniques on one endpoint may indicate that the attacker wanted redundant methods for maintaining access. Discovery is used to learn about systems and accounts, exfiltration involves removing data, and reconnaissance generally concerns information gathering. During eradication, analysts must remove all persistence mechanisms rather than deleting only the primary payload. The SOC should also search other systems for equivalent scheduled tasks, services, registry changes, and filenames because the attacker may have deployed the same persistence strategy throughout the environment.<\/span><\/p>\n<p><b>Question 98.<\/b><\/p>\n<p><b>Which incident-response action should normally occur after containment but before normal business operations are restored?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore remaining persistence because the host is isolated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Eradicate malware, persistence, and the underlying cause<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete investigation records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After containment limits the immediate spread or impact of an incident, the team should eradicate the malicious components and underlying causes. Eradication may include removing malware, persistence mechanisms, unauthorized accounts, malicious scheduled tasks, or compromised credentials and patching exploited vulnerabilities. Simply isolating a host is not sufficient because reconnecting it without eliminating the attacker&#8217;s foothold could immediately reintroduce the threat. Investigation records and monitoring should be preserved, not removed. Depending on the severity of compromise, rebuilding from a known-good image may provide greater assurance than manually cleaning the system. Recovery should begin only after the team has sufficient confidence that the threat has been removed.<\/span><\/p>\n<p><b>Question 99.<\/b><\/p>\n<p><b>Which activity belongs primarily to the recovery phase of incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring cleaned or rebuilt systems to production and monitoring them closely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Creating the incident-response plan for the first time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Gathering pre-incident threat intelligence only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Purchasing employee laptops<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery focuses on safely returning systems and services to normal operation after containment and eradication have addressed the active threat. Activities may include restoring data, rebuilding systems, validating security controls, reconnecting hosts to production networks, and closely monitoring for recurrence. A system should not simply be reconnected because malware files were deleted; the organization needs confidence that persistence, compromised credentials, and exploited weaknesses were addressed. Preparation occurs before an incident, while threat intelligence can support multiple phases. Careful post-recovery monitoring is essential because renewed command-and-control traffic or suspicious authentication may reveal that eradication was incomplete.<\/span><\/p>\n<p><b>Question 100.<\/b><\/p>\n<p><b>After a major incident, the SOC determines that several important log sources were unavailable during the investigation. What should be the highest-priority post-incident improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce log collection further to save storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete existing incident evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Improve telemetry coverage, retention, and monitoring for the missing sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable correlation rules until the next incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Missing telemetry is a significant detection and investigation gap. The post-incident review should identify which logs were unavailable, why they were missing, and what changes are needed to ensure future collection and retention. This could involve enabling endpoint process telemetry, improving identity logging, sending firewall or proxy events to the SIEM, increasing retention, fixing parsing, or monitoring ingestion health. The organization should also verify that timestamps are synchronized and that important fields are normalized correctly. Reducing logging or deleting evidence would make future investigations more difficult. Lessons learned are most valuable when they result in measurable defensive improvements, such as stronger telemetry, updated detection rules, improved playbooks, and clearer ownership for monitoring failures.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 81. A security analyst observes a user account successfully authenticating from an internal workstation and then accessing several servers the user has never contacted before. Which activity should the analyst investigate first? Potential lateral movement using compromised credentials 2. Routine DHCP [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23774"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23774"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23774\/revisions"}],"predecessor-version":[{"id":23775,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23774\/revisions\/23775"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}