{"id":23778,"date":"2026-09-28T09:56:50","date_gmt":"2026-09-28T09:56:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23778"},"modified":"2026-09-28T09:56:50","modified_gmt":"2026-09-28T09:56:50","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 121.<\/b><\/p>\n<p><b>An analyst needs to determine whether a suspicious endpoint communicated with other internal hosts before it was isolated. Which source would provide the most useful network-level evidence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer configuration history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Building access records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> NetFlow or network telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS inventory information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and similar network telemetry can reveal communication relationships between endpoints by recording information such as source and destination IP addresses, ports, protocols, timestamps, and traffic volumes. This is particularly useful when analysts need to identify internal systems contacted by a potentially compromised host before containment. Unlike full packet capture, flow records generally do not contain payload content, but they provide efficient visibility over large networks and can support retrospective analysis. Printer, physical access, and BIOS records do not provide meaningful network-communication evidence. Analysts should correlate flow data with DNS, firewall, authentication, and endpoint telemetry to determine whether the observed connections represent normal business activity, lateral movement, scanning, or command-and-control behavior.<\/span><\/p>\n<p><b>Question 122.<\/b><\/p>\n<p><b>Which forensic principle should an investigator follow to reduce the risk of unintentionally modifying original digital evidence during analysis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyze a verified forensic copy rather than the original evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Open every file directly from the original disk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable hashing to improve acquisition speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change timestamps before examination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Investigators should preserve original evidence whenever possible and perform analysis on a verified forensic copy. This reduces the risk of changing file metadata, timestamps, file-system structures, or other artifacts on the original device. A forensic image should be acquired using approved procedures and validated with cryptographic hashes so investigators can demonstrate that the copy accurately represents the source. Directly opening files from original evidence can alter access times or other metadata, while changing timestamps would compromise forensic integrity. Hashing should not be removed merely for speed because integrity verification is fundamental to defensible forensic work. Proper evidence handling should also include chain-of-custody documentation, controlled access, and secure evidence storage.<\/span><\/p>\n<p><b>Question 123.<\/b><\/p>\n<p><b>An endpoint alert shows <\/b><b>powershell.exe<\/b><b> launching from a Microsoft Word process after a document was opened. Which artifact should the analyst review next to determine what PowerShell actually attempted to do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Monitor serial number<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Physical access logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> PowerShell command-line and script-block telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PowerShell command-line and script-block telemetry can reveal the actual commands, parameters, encoded content, download locations, and execution behavior associated with suspicious PowerShell activity. When Word launches PowerShell shortly after a document is opened, the process relationship itself is suspicious, but analysts need the command details to understand whether the activity downloaded malware, created persistence, accessed credentials, or performed another action. DHCP information may help identify a host at a certain time, but it does not explain script execution. Physical and hardware inventory data are similarly unrelated. Analysts should also correlate PowerShell activity with resulting child processes, file writes, registry changes, DNS queries, and outbound network connections.<\/span><\/p>\n<p><b>Question 124.<\/b><\/p>\n<p><b>A SOC observes one endpoint attempting connections to hundreds of internal TCP ports and systems over a short period. Which behavior is most likely being observed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Network discovery or scanning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Normal DHCP activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk imaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connections to many internal systems and ports over a short time can indicate network discovery or scanning. Attackers often perform this activity after gaining an initial foothold to identify reachable hosts, services, databases, administrative interfaces, and potential lateral-movement targets. Legitimate vulnerability scanners and management tools can produce similar patterns, so analysts should identify the originating process, source host role, authorized scanning schedules, and account context before classifying the behavior as malicious. DHCP does not normally produce wide-ranging TCP connection attempts, and disk imaging or data compression does not explain the observed network behavior. Network flow telemetry, firewall logs, EDR data, and asset inventory can help distinguish authorized scanning from attacker reconnaissance.<\/span><\/p>\n<p><b>Question 125.<\/b><\/p>\n<p><b>Which Cisco security technology is designed to provide endpoint visibility, malware detection, and response capabilities on protected systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cisco Secure Endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Cisco IOS routing only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cisco IP SLA<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Cisco Discovery Protocol<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Secure Endpoint is designed to provide endpoint-oriented security capabilities such as malware detection, file and process visibility, retrospective analysis, and response support. Endpoint telemetry is particularly useful during incident investigations because analysts can review process relationships, file activity, network connections, and other behavior associated with a suspected compromise. Cisco IOS routing, IP SLA, and CDP have important networking functions but are not endpoint detection and response platforms. Analysts should combine endpoint findings with broader telemetry such as firewall, DNS, identity, email, and flow information. No single security product provides complete incident visibility, so correlation across multiple sources remains important when scoping and responding to a compromise.<\/span><\/p>\n<p><b>Question 126.<\/b><\/p>\n<p><b>An analyst receives an alert that a known malicious file was observed on an endpoint three weeks ago, before threat intelligence classified the file as malicious. Which capability is most useful in this scenario?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical access review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Retrospective analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Manual IP addressing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk defragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Retrospective analysis allows analysts to search historical telemetry for files, indicators, or behaviors that were not known to be malicious when originally observed. Once new intelligence identifies a file hash or other artifact as malicious, security teams can search endpoint and network history to determine whether the indicator appeared previously. This can uncover infections that were missed at the time and can significantly expand the known incident timeline. Physical access review and disk maintenance are unrelated. Retrospective analysis depends on sufficient telemetry retention, accurate timestamps, and searchable historical data. Analysts should also pivot beyond the exact file hash to associated processes, network destinations, persistence mechanisms, and related hosts because attackers may have used modified variants.<\/span><\/p>\n<p><b>Question 127.<\/b><\/p>\n<p><b>Which data source would best help identify whether a compromised endpoint transferred an unusually large amount of data to an external system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User wallpaper configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> NetFlow or firewall traffic records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS password status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and firewall traffic records can reveal traffic volume, source and destination addresses, ports, protocols, and session timing. This makes them useful for identifying unusual outbound transfers that may indicate data exfiltration. Analysts should compare current activity with historical baselines and the normal role of the host. A workstation sending several gigabytes to a rare external destination may warrant investigation, while similar traffic from an approved backup server may be expected. Flow records may not reveal the transferred content, so endpoint telemetry, proxy data, data-loss prevention systems, or packet capture may be needed for additional context. Hardware and printer information do not provide relevant traffic-volume evidence.<\/span><\/p>\n<p><b>Question 128.<\/b><\/p>\n<p><b>Which condition would most strongly increase confidence that a large outbound data transfer represents exfiltration rather than legitimate business traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The transfer occurs during normal business hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The destination uses TCP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The workstation has an SSD<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A sensitive archive was created immediately before the transfer to a rare external destination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The combination of suspicious file staging and unusual outbound transfer behavior provides stronger evidence of potential exfiltration than either signal alone. If an endpoint creates a large archive containing sensitive documents and then sends a similar amount of data to a destination rarely contacted by the organization, the sequence is particularly concerning. Analysts should inspect the archive contents, responsible process, user account, destination reputation, protocol, and whether encryption or cloud storage was used. Business applications can legitimately compress and transfer data, so context remains important. Time of day and use of TCP are weak indicators by themselves. Correlating endpoint and network evidence improves confidence while reducing false positives.<\/span><\/p>\n<p><b>Question 129.<\/b><\/p>\n<p><b>A compromised workstation queries many internal hostnames and Active Directory objects immediately after initial execution. Which MITRE ATT&amp;CK tactic best describes this activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Discovery describes adversary activities intended to learn about the victim environment after access has been obtained. Attackers may enumerate hosts, users, groups, domains, network configuration, security software, shares, or other resources before choosing lateral-movement or privilege-escalation targets. Querying many internal hostnames and directory objects fits this objective. Exfiltration concerns removing data, Persistence focuses on maintaining access, and Impact relates to disrupting systems or data. Discovery behavior can resemble legitimate administrative activity, so analysts should consider the account, process, endpoint role, frequency, and timing. Mapping activity to MITRE ATT&amp;CK can help defenders communicate findings consistently and identify opportunities for improved detections.<\/span><\/p>\n<p><b>Question 130.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic is most closely associated with an attacker attempting to disable endpoint security software or clear logs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Defense Evasion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Resource Development<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense Evasion includes techniques adversaries use to avoid detection, bypass controls, hide artifacts, or interfere with security mechanisms. Disabling endpoint protection, clearing event logs, changing security settings, and disguising malicious files can all support this objective. Collection concerns gathering target data, Reconnaissance relates to gathering information about a target, and Resource Development generally concerns preparing infrastructure or capabilities before or during operations. Attempts to disable security products should receive high investigative priority because they may indicate that an attacker is actively attempting to reduce visibility before continuing with credential theft, lateral movement, or data theft. Analysts should preserve available telemetry and determine whether other hosts show similar defensive-control tampering.<\/span><\/p>\n<p><b>Question 131.<\/b><\/p>\n<p><b>An analyst finds a Windows event log was cleared shortly after a suspicious administrator login. Why is this significant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It may indicate an attempt to remove evidence or evade detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Clearing logs automatically patches Windows<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It proves the administrator account owner is malicious<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It increases network throughput<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clearing security or system logs after suspicious activity can indicate an attempt to remove evidence and evade detection. However, it does not prove that the legitimate owner of the administrator account performed the action; the credentials may have been compromised. Analysts should correlate the log-clearing event with authentication records, endpoint process telemetry, remote access activity, and other centralized logs that may remain available even when local logs are removed. If logs are forwarded to a SIEM or centralized collector, attackers may be unable to erase those copies. The event should also prompt investigation for other defense-evasion behavior. Centralized, immutable, or otherwise protected logging substantially improves incident resilience when local systems are compromised.<\/span><\/p>\n<p><b>Question 132.<\/b><\/p>\n<p><b>Which practice best protects security logs from being destroyed by an attacker who gains local administrator access to an endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store all logs only on the endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Forward logs to a centralized protected logging platform<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable logging after successful authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow every user to modify logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Forwarding logs to a centralized and appropriately protected platform reduces dependence on the compromised endpoint. Even if an attacker clears local event logs, copies already transmitted to a SIEM or logging platform may remain available for investigation. Centralized logging also enables correlation across systems and helps identify attacks that span multiple endpoints. Log repositories should use access controls, appropriate retention, time synchronization, and monitoring for ingestion failures. Keeping the only copy locally allows an administrator-level attacker to remove critical evidence. Disabling or broadly exposing logs would further weaken security. Analysts should also monitor for sudden gaps in log transmission because attackers may attempt to stop forwarding before performing malicious actions.<\/span><\/p>\n<p><b>Question 133.<\/b><\/p>\n<p><b>A security analyst notices that a workstation stopped sending endpoint telemetry five minutes before suspicious authentication activity began. What should the analyst consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint sensor may have been disabled or disrupted as part of the attack<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The event proves the workstation was powered off<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Missing telemetry is always a network maintenance issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The incident can be closed because there is insufficient data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sudden loss of security telemetry immediately before suspicious activity can indicate sensor tampering, service termination, network disruption, or another defense-evasion technique. Analysts should not automatically assume malicious intent, because software failures or connectivity problems can also cause telemetry gaps. The event should be correlated with endpoint service logs, network records, security alerts, system uptime, and administrative activity. If an attacker disabled the EDR agent before using stolen credentials, that sequence may significantly increase incident severity. Missing data should itself be treated as an investigative clue rather than a reason to close the case. Monitoring sensor health and alerting on unexpected telemetry loss improves security visibility.<\/span><\/p>\n<p><b>Question 134.<\/b><\/p>\n<p><b>Which source is most useful for determining whether a suspicious user account was used to establish a remote desktop session to a Windows server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer audit records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows authentication and Remote Desktop-related logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP scope size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Asset purchase receipts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows authentication and Remote Desktop-related event logs can provide details about successful or failed remote sessions, usernames, source addresses, logon types, and session activity. These records can help analysts determine whether a compromised account was used for lateral movement through RDP. Endpoint telemetry on both source and destination hosts can add process and command context after login. DHCP logs may assist with associating a source IP with a device at the relevant timestamp, but they are not the primary evidence for the RDP session itself. Investigators should compare the login with the user&#8217;s normal behavior and determine what actions occurred once the remote session was established.<\/span><\/p>\n<p><b>Question 135.<\/b><\/p>\n<p><b>Which incident-response decision should generally be made before reconnecting a rebuilt system to production?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirm that the system is patched, security controls are operational, and compromise indicators are absent<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restore the attacker&#8217;s persistence mechanism for testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete every investigation record<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before a rebuilt or remediated system is returned to production, the response team should verify that the operating system and applications are patched, required security controls are active, compromised credentials have been addressed, and known malicious artifacts are absent. The system should also be monitored closely after reconnection for signs of recurrence. Recovery should not be rushed merely because business pressure exists, because reconnecting an incompletely remediated system can reintroduce the attacker to the environment. Disabling monitoring or restoring persistence would directly increase risk. Investigation records should be retained according to organizational policy so the incident can be reviewed and lessons can be incorporated into future defenses.<\/span><\/p>\n<p><b>Question 136.<\/b><\/p>\n<p><b>During an investigation, an analyst finds that malware communicates with its controller only once every eight hours. Why can this technique complicate detection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It causes every firewall to stop logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It prevents endpoint telemetry from working<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically encrypts all traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Low-frequency beaconing can blend into normal background network activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Low-frequency beaconing reduces the number of observable network events and can make malicious communication harder to distinguish from ordinary background traffic. A connection every several hours may not trigger simple rules designed to identify highly regular or frequent command-and-control traffic. Analysts may need longer observation windows, historical flow data, rare-destination analysis, endpoint process context, and threat intelligence to identify such behavior. Low frequency does not automatically disable logging or encrypt traffic. Attackers may also add timing variation, called jitter, to make patterns less obvious. Behavioral analysis that combines rarity, destination reputation, process identity, and historical baselines can improve detection of slow command-and-control activity.<\/span><\/p>\n<p><b>Question 137.<\/b><\/p>\n<p><b>An analyst identifies command-and-control traffic from one endpoint. Which hunting strategy is most likely to reveal additional compromised systems using the same malware family?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search for related domains, IPs, certificates, process patterns, and beaconing behavior across the environment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Examine only the affected user&#8217;s wallpaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace network switches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable DNS logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A broad hunt should use both static indicators and behavioral characteristics. Related domains, IP addresses, TLS certificates, file hashes, process relationships, command lines, persistence artifacts, and similar beaconing patterns can all help identify additional compromised hosts. Relying on only one hash or domain can miss variants because attackers frequently change infrastructure and malware files. Disabling logging would remove useful visibility, while hardware replacement is unwarranted without evidence of device failure. Hunting across multiple telemetry sources allows analysts to determine whether the initial compromise was isolated or part of a wider campaign. Confirmed findings can then be converted into improved detection rules and response playbooks.<\/span><\/p>\n<p><b>Question 138.<\/b><\/p>\n<p><b>Which evidence would most strongly indicate that a malicious actor used a compromised account to access a file server and collect sensitive documents?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user owns a laptop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Authentication to the file server followed by unusual bulk file access from the same account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The file server uses NTFS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The user has a corporate email address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication followed immediately by unusual bulk access to sensitive files provides a meaningful sequence supporting the hypothesis that the account was used for collection. Analysts should examine the source host, authentication method, accessed directories, file types, volume of data read, historical user behavior, and whether archive creation or exfiltration followed. Simply having an account or using a common file system provides little evidence. The account owner may also be a victim rather than the attacker, so conclusions should focus on the activity and supporting telemetry rather than assuming insider intent. Identity, file-access auditing, EDR, and network data together can help reconstruct the attack sequence.<\/span><\/p>\n<p><b>Question 139.<\/b><\/p>\n<p><b>A SOC determines that a detection failed because a critical log source was not being parsed correctly by the SIEM. What should be done after correcting the parser?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test ingestion and detection logic using representative events and search historical data if available<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume the issue is fixed without validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable the log source<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shorten retention to one hour<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After correcting a parsing problem, the SOC should validate that events are being ingested, normalized, and mapped to expected fields correctly. Detection rules relying on those fields should then be tested with representative data. If raw historical logs remain available, analysts should consider retrospective searches to determine whether earlier malicious events were missed during the parsing failure. Simply changing the parser without validation could leave the same visibility gap in place. Disabling the source or drastically shortening retention would worsen the problem. Monitoring data-pipeline health, parser failures, and source-volume changes is an important operational control because detection logic cannot function reliably when underlying telemetry is incomplete or malformed.<\/span><\/p>\n<p><b>Question 140.<\/b><\/p>\n<p><b>A post-incident review shows that analysts repeatedly performed the same manual containment and enrichment steps. Which improvement is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove the incident-response playbook<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Stop collecting contextual data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automate suitable repeatable tasks while preserving analyst approval for high-impact actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable alerts that require investigation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeatable enrichment and low-risk response steps are strong candidates for automation. Automated workflows can gather asset criticality, user information, threat-intelligence reputation, recent authentication events, endpoint details, and other context before an analyst begins investigation. Certain containment actions may also be automated or semi-automated when organizational policy permits, but high-impact actions such as disabling critical accounts or isolating production systems may still require analyst approval. Automation should increase consistency and speed without removing necessary judgment. Eliminating contextual data or suppressing alerts would reduce security effectiveness. Post-incident reviews should identify repetitive work and convert it into tested, documented workflows that shorten response time while maintaining appropriate controls.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 121. An analyst needs to determine whether a suspicious endpoint communicated with other internal hosts before it was isolated. Which source would provide the most useful network-level evidence? Printer configuration history 2. Building access records 3. NetFlow or network telemetry 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23778"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23778"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23778\/revisions"}],"predecessor-version":[{"id":23779,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23778\/revisions\/23779"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}