{"id":23782,"date":"2026-09-28T09:58:00","date_gmt":"2026-09-28T09:58:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23782"},"modified":"2026-09-28T09:58:00","modified_gmt":"2026-09-28T09:58:00","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161.<\/b><\/p>\n<p><b>A security analyst discovers that a compromised endpoint resolved several suspicious domains before contacting an external IP address. Which investigative step provides the best way to expand the scope of the incident?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search DNS, proxy, firewall, and endpoint telemetry for the domains and related IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace the endpoint network adapter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all DNS logs after blocking the domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable name resolution across the enterprise<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Searching across multiple telemetry sources allows the analyst to determine whether the same malicious infrastructure was contacted by other systems. DNS logs can show which endpoints resolved the domains, proxy logs can reveal web requests, firewall records can confirm outbound network connections, and endpoint telemetry can identify which processes initiated those communications. Related IP addresses, file hashes, certificates, and URLs can provide additional pivots. Replacing hardware or disabling DNS would be disruptive without helping reconstruct historical activity. Deleting logs would destroy important evidence. Incident scoping is strongest when analysts pivot systematically from known indicators to associated hosts, users, processes, and timestamps rather than investigating one artifact in isolation.<\/span><\/p>\n<p><b>Question 162.<\/b><\/p>\n<p><b>Which security capability is most appropriate for discovering whether a newly identified malicious behavior occurred on endpoints before a formal detection rule existed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asset depreciation analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Retrospective threat hunting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer maintenance review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static IP assignment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Retrospective threat hunting uses historical telemetry to search for behavior that was not previously recognized as malicious. Once analysts learn that attackers use a specific process chain, command pattern, domain, persistence mechanism, or network behavior, they can search retained EDR, SIEM, DNS, proxy, and firewall data for earlier occurrences. This may reveal previously undetected compromise and help establish the true beginning of an incident. The usefulness of retrospective analysis depends heavily on telemetry quality and retention. Asset depreciation, printer maintenance, and addressing configuration do not provide historical attack visibility. Findings from retrospective hunts can also be converted into new detections so future instances generate alerts automatically.<\/span><\/p>\n<p><b>Question 163.<\/b><\/p>\n<p><b>A user account that normally accesses one application server suddenly authenticates to twelve servers in three minutes. Which security concept is most useful for recognizing this behavior as unusual?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deduplication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Signature validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Behavioral baselining<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk imaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral baselining establishes what normal activity looks like for a particular user, host, or application. If a user typically accesses one server but suddenly authenticates to twelve systems in rapid succession, the deviation may indicate lateral movement, credential misuse, or automated malicious activity. The analyst should correlate authentication events with source-device telemetry, privilege level, remote execution activity, and subsequent access. A deviation is not automatically malicious because legitimate responsibilities can change, but it provides strong context for prioritization. Signature validation and disk imaging serve different purposes, while deduplication is unrelated. Behavioral baselines are especially valuable when attackers use valid credentials and legitimate administration tools.<\/span><\/p>\n<p><b>Question 164.<\/b><\/p>\n<p><b>Which event would most strongly indicate malicious lateral movement after a successful remote authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The remote server responds to ping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The user opens an approved intranet page<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The destination host performs a normal scheduled backup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A new remote service is created and executes an unfamiliar binary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote service creation followed by execution of an unfamiliar binary is strongly associated with lateral movement and remote code execution techniques. If this occurs immediately after unusual authentication, the combined sequence significantly increases confidence that the account or originating host is compromised. Analysts should review the service name, executable path, file hash, user context, source host, destination host, and whether the same behavior appears elsewhere. A ping response or routine backup provides little evidence of compromise. Once lateral movement is confirmed, the incident should be scoped broadly because additional credentials or systems may already be affected. Containment may require isolating multiple hosts and restricting compromised accounts.<\/span><\/p>\n<p><b>Question 165.<\/b><\/p>\n<p><b>A SOC analyst sees a process named <\/b><b>lsass.exe<\/b><b> running from a user&#8217;s temporary directory. Why is this suspicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The legitimate process is normally expected to run from a trusted Windows system location<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows never uses a process named <\/span><span style=\"font-weight: 400;\">lsass.exe<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Temporary directories cannot contain executable files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> All processes in temporary directories are automatically malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers often use filenames that imitate trusted Windows processes to make malicious software appear legitimate. The legitimate <\/span><span style=\"font-weight: 400;\">lsass.exe<\/span><span style=\"font-weight: 400;\"> normally executes from a protected Windows system location, so an identically named executable running from a user temporary directory is a strong anomaly. Analysts should verify the file path, digital signature, hash, parent process, command line, file creation time, and network behavior. The filename alone does not prove maliciousness because a benign file could theoretically use the same name, but the location mismatch raises suspicion. Path-aware detection is often more effective than process-name-only detection because adversaries can easily choose familiar filenames.<\/span><\/p>\n<p><b>Question 166.<\/b><\/p>\n<p><b>Which data source would best help determine whether a suspicious process created a scheduled task for persistence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network switch temperature logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint telemetry and Windows task creation events<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Badge access records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer queue history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint telemetry and Windows task creation events can reveal when scheduled tasks are created, modified, or executed. These records may include the task name, command being run, user account, creation time, and process responsible for the change. Scheduled tasks are frequently used for legitimate administration, but they can also provide persistence or recurring execution for malware. Analysts should evaluate whether the task path, executable, account, and schedule are consistent with normal behavior. Badge and printer records cannot provide this process-level information. If malicious persistence is confirmed, the SOC should search other hosts for the same task name, command, or related binary to determine whether the attacker deployed it more broadly.<\/span><\/p>\n<p><b>Question 167.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic is most closely associated with the use of scheduled tasks, startup items, or services to maintain access after reboot?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Impact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Persistence covers techniques adversaries use to maintain access to systems despite reboots, logoffs, credential changes, or other interruptions. Scheduled tasks, malicious services, registry startup entries, startup folders, and unauthorized accounts are common examples. Reconnaissance involves gathering information about targets, Collection involves gathering data for later use, and Impact concerns disrupting systems or data. Persistence artifacts are especially important during eradication because removing the visible malware payload without eliminating persistence may allow the attacker to regain execution. Analysts should also search for multiple redundant persistence methods because sophisticated intrusions may establish more than one foothold on the same host.<\/span><\/p>\n<p><b>Question 168.<\/b><\/p>\n<p><b>A security analyst observes a large encrypted archive being created from sensitive documents and then uploaded to a cloud-storage domain rarely used by the organization. Which activity is most likely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Routine DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Normal endpoint patching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS recursion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data staging and exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The sequence of collecting sensitive documents, packaging them into a large encrypted archive, and transferring that archive to an unusual cloud-storage destination is highly consistent with data staging and exfiltration. Analysts should determine which process created the archive, which files were included, the user account involved, destination reputation, transfer size, and whether the cloud service is approved. Legitimate backup or business workflows can produce similar behavior, so context remains necessary. DHCP, DNS, and patching do not explain the combined archive-and-upload sequence. If exfiltration is confirmed, containment should focus on stopping further transfer while preserving evidence and identifying all affected data and systems.<\/span><\/p>\n<p><b>Question 169.<\/b><\/p>\n<p><b>Which network telemetry is most useful for identifying unusually large outbound transfers when packet payloads are not available?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NetFlow or similar flow records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Monitor EDID information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Keyboard layout<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and similar flow technologies record metadata such as source and destination addresses, ports, protocols, timestamps, duration, and byte or packet counts. This allows analysts to identify large outbound transfers even when the actual payload is not captured. Flow records are particularly useful for broad enterprise visibility because they require significantly less storage than full packet capture. Analysts can compare traffic volumes against historical baselines and investigate rare destinations, unusual ports, and affected endpoint roles. NetFlow cannot reveal exact file contents, so endpoint, DLP, proxy, or packet data may be required for deeper analysis. Hardware and keyboard information are unrelated to network transfer volume.<\/span><\/p>\n<p><b>Question 170.<\/b><\/p>\n<p><b>What is the primary advantage of full packet capture over flow telemetry during a network investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always requires less storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It can provide packet-level protocol details and payload content when traffic is not encrypted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically identifies the attacker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for endpoint telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Full packet capture records packet-level information and can provide protocol headers, transaction details, transferred content, commands, and other evidence that flow telemetry does not retain. This makes packet capture especially useful when analysts need to reconstruct a session or inspect application behavior. The trade-off is higher storage requirements and potentially greater privacy considerations. Encrypted protocols may still prevent payload inspection unless appropriate decryption capabilities exist. Packet capture also does not replace identity or endpoint telemetry because it may show what communication occurred without identifying the local process or user responsible. Strong investigations therefore combine network packets with endpoint, identity, DNS, and application logs.<\/span><\/p>\n<p><b>Question 171.<\/b><\/p>\n<p><b>A security analyst finds that several hosts stopped forwarding logs shortly before suspicious activity occurred. What should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether logging agents or services were disabled as part of defense evasion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Monitor brightness configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer toner levels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP scope naming conventions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sudden loss of logging from multiple hosts immediately before suspicious activity can indicate tampering with log agents, endpoint sensors, services, or network paths. Attackers may disable security tooling or log forwarding to reduce visibility before performing credential theft, lateral movement, or data exfiltration. Analysts should check agent health, service status, process termination events, administrative activity, network connectivity, and centralized monitoring alerts. Operational failures are also possible, so the event must be validated rather than assumed malicious. Logging gaps themselves are important evidence and should not be ignored. Monitoring telemetry health is a critical defensive capability because detections cannot work properly when log sources silently disappear.<\/span><\/p>\n<p><b>Question 172.<\/b><\/p>\n<p><b>Which practice best protects investigation data if an attacker gains administrative control of an endpoint and clears local logs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep the only copy of logs on the endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable log forwarding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Forward logs to a centralized protected repository<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow all users to modify log files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging helps preserve evidence even if the local endpoint is compromised. Events that have already been transmitted to a SIEM or protected log platform may remain available after an attacker clears local logs. Centralized collection also supports cross-system correlation and longer retention. The repository itself should have strict access controls, reliable time synchronization, monitored ingestion, and protections against unauthorized modification. Keeping the only copy locally gives an attacker with administrative rights an easy way to destroy evidence. Security teams should also alert on unexpected reductions in event volume or agent health because attackers may try to stop forwarding before clearing local data.<\/span><\/p>\n<p><b>Question 173.<\/b><\/p>\n<p><b>Which forensic artifact should generally be collected early because it may disappear when a system loses power?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Volatile memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Asset purchase documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printed rack diagram<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware warranty information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Volatile memory can contain active processes, injected code, network connections, credentials, encryption keys, command history, and other transient artifacts that may disappear after shutdown. When organizational procedures permit, memory acquisition may therefore occur before powering off a compromised system. Analysts must balance evidence preservation against containment because leaving a system connected while collecting memory could allow ongoing malicious activity. The resulting image should be documented, hashed, and protected appropriately. Physical paperwork and warranty data are persistent and do not require urgent collection. Order of volatility is an important forensic concept because some evidence sources are far more time-sensitive than others.<\/span><\/p>\n<p><b>Question 174.<\/b><\/p>\n<p><b>Which forensic control documents every transfer and person who handled evidence during an investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Chain of custody<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network segmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data normalization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Chain of custody documents who collected, possessed, transferred, stored, and analyzed evidence throughout an investigation. It helps demonstrate that the evidence was handled properly and was not substituted, lost, or modified without authorization. A typical record includes evidence identifiers, dates, times, handlers, transfer details, and storage locations. File compression does not document handling, while network segmentation and normalization serve unrelated technical purposes. Chain of custody is particularly important when evidence may support legal, disciplinary, regulatory, or law-enforcement actions. It should be combined with cryptographic hashes, secure storage, restricted access, and repeatable forensic procedures to preserve integrity and defensibility.<\/span><\/p>\n<p><b>Question 175.<\/b><\/p>\n<p><b>Why should a cryptographic hash be calculated after creating a forensic disk image?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To verify the integrity of the acquired evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To increase the image storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To remove malware automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To improve network bandwidth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash produces a reproducible value based on the evidence content. By recording the hash immediately after acquisition and comparing it later, investigators can verify that the forensic image has remained unchanged. This provides integrity assurance and supports chain-of-custody documentation. Hashing does not increase capacity, remove malware, or improve network performance. Investigators generally preserve the original evidence and perform analysis on verified working copies. If the hash changes unexpectedly, the discrepancy should be investigated because it may indicate modification, corruption, or a problem with the acquisition process. Evidence integrity is essential for reliable forensic conclusions and for any investigation that may face formal review.<\/span><\/p>\n<p><b>Question 176.<\/b><\/p>\n<p><b>Which device is commonly used during forensic disk acquisition to prevent modifications to the original storage media?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IDS sensor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Network tap<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Load balancer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Write blocker<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A write blocker prevents the forensic workstation from writing data to the original storage media during acquisition. This helps preserve metadata, timestamps, file-system structures, and other evidence. Hardware write blockers are common, although validated software approaches can also be used depending on procedures. Network taps and IDS sensors support network monitoring, while load balancers distribute traffic. A write blocker does not replace hashing, documentation, or chain of custody; it is one component of proper evidence handling. Investigators should still validate the forensic image and document the tools, operator, date, time, and storage location associated with acquisition.<\/span><\/p>\n<p><b>Question 177.<\/b><\/p>\n<p><b>A compromised system is actively spreading malware to other hosts. Which incident-response action should receive immediate priority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Contain the affected system to limit propagation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Write the final lessons-learned report<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Purchase replacement hardware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete every event log<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment should receive immediate priority when a system is actively spreading malware because continued connectivity can increase the number of affected hosts and expand business impact. Containment may involve EDR isolation, firewall rules, switch controls, account restrictions, or physical network disconnection depending on organizational procedures. Evidence preservation still matters, so the response team should balance rapid containment with the need to capture volatile data when feasible. Lessons learned occurs after recovery, and deleting logs would destroy valuable evidence. Once propagation is stopped, analysts can continue scoping the incident and move into eradication by removing malware, persistence, compromised credentials, and the original infection vector.<\/span><\/p>\n<p><b>Question 178.<\/b><\/p>\n<p><b>Which action belongs primarily to the eradication phase rather than containment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Isolating a workstation from the network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Removing malware, persistence mechanisms, and exploited weaknesses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Blocking an external IP temporarily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Restricting a compromised account while investigation continues<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication addresses the underlying malicious components and root causes after immediate spread has been limited. This includes removing malware, deleting malicious services or scheduled tasks, resetting compromised credentials, patching exploited vulnerabilities, and removing unauthorized tools. Isolation, temporary IP blocking, and account restrictions are commonly containment actions because they reduce immediate risk while investigation continues. Eradication must be thorough because leaving a persistence mechanism or stolen credential in place can allow the attacker to return. In heavily compromised systems, rebuilding from a trusted image may be safer than attempting manual cleanup. Recovery should begin only after the response team has reasonable confidence that attacker access has been eliminated.<\/span><\/p>\n<p><b>Question 179.<\/b><\/p>\n<p><b>Which activity belongs primarily to the recovery phase of incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Safely restoring systems to production and monitoring for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Creating the incident-response plan for the first time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Developing threat intelligence before any event occurs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Establishing hardware procurement contracts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery focuses on returning remediated systems and services to normal operation in a controlled manner. The team should verify that systems are patched, security controls are enabled, compromised credentials have been addressed, data has been restored as necessary, and malicious indicators are absent. Systems are then reconnected and monitored closely for recurrence. Preparation activities such as creating plans occur before incidents. Threat intelligence can support many stages but is not itself recovery. Enhanced monitoring after restoration is important because renewed beaconing, persistence execution, or suspicious authentication may reveal incomplete eradication. Recovery should prioritize both business continuity and confidence that the environment is safe.<\/span><\/p>\n<p><b>Question 180.<\/b><\/p>\n<p><b>A post-incident review determines that several detections existed but analysts did not know which alerts should be escalated quickly. Which improvement would most directly address the problem?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce log retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable high-severity alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Develop clearer triage criteria, playbooks, and escalation procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop collecting contextual information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clear triage criteria and escalation procedures help analysts consistently determine which alerts require immediate action. Playbooks can define what evidence to collect, how to evaluate severity, which assets or accounts increase risk, when to contain systems, and when incidents should be escalated to senior responders or management. Detection alone is not enough if analysts lack a consistent process for interpreting and prioritizing alerts. Reducing telemetry or disabling high-severity alerts would worsen the problem. Mature SOC operations combine strong detections with asset context, user privilege information, threat intelligence, documented workflows, and periodic exercises. Post-incident lessons should result in practical changes that reduce future detection-to-response time.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 161. A security analyst discovers that a compromised endpoint resolved several suspicious domains before contacting an external IP address. Which investigative step provides the best way to expand the scope of the incident? Search DNS, proxy, firewall, and endpoint telemetry for [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23782"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23782"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23782\/revisions"}],"predecessor-version":[{"id":23783,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23782\/revisions\/23783"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}