{"id":23784,"date":"2026-09-28T09:58:15","date_gmt":"2026-09-28T09:58:15","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23784"},"modified":"2026-09-28T09:58:15","modified_gmt":"2026-09-28T09:58:15","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 181.<\/b><\/p>\n<p><b>A SOC analyst notices that a user account successfully authenticated to a critical server from a host that has never previously accessed that server. Which factor would most strongly increase the likelihood of compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The source host was previously associated with malware activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The destination server uses a static IP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The user has logged in during business hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The server is located in the same data center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A source host already associated with malware activity significantly increases the likelihood that the authentication represents credential abuse or lateral movement. The analyst should correlate the login with endpoint telemetry from the source host, review the account&#8217;s privilege level, determine whether MFA was used, and inspect activity on the destination server immediately after authentication. A static IP address, normal working hours, or physical proximity between systems does not meaningfully reduce or increase the malicious hypothesis. Context matters because a valid login alone is not proof of compromise. Strong investigations combine identity, endpoint, network, and historical baseline data before determining whether containment is required.<\/span><\/p>\n<p><b>Question 182.<\/b><\/p>\n<p><b>Which telemetry source is most useful for determining whether a user downloaded a malicious file through a corporate web gateway?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Power-supply logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Proxy or secure web gateway logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Monitor configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Proxy and secure web gateway logs can provide requested URLs, domains, usernames, source IP addresses, timestamps, response codes, user agents, and sometimes file or byte-transfer information. This makes them highly useful for identifying web-based malware delivery and determining which user or endpoint initiated the download. Analysts should correlate the web request with endpoint telemetry to confirm whether the file was saved, executed, or blocked. Hardware configuration sources do not provide this application-layer visibility. If the connection was encrypted and the organization does not perform TLS inspection, metadata may still help establish timing and destination context, while EDR can provide the process-level evidence needed to complete the investigation.<\/span><\/p>\n<p><b>Question 183.<\/b><\/p>\n<p><b>A SOC rule identifies a user visiting a domain that has never before been seen in the environment and was registered two days ago. Which additional factor would most increase suspicion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint has a large amount of RAM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The domain uses HTTPS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The domain is contacted immediately after a suspicious PowerShell process launches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The workstation uses DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A newly registered and previously unseen domain becomes more suspicious when the connection occurs immediately after a suspicious process launches. This temporal relationship may indicate malware delivery or command-and-control activity. The analyst should inspect the PowerShell command line, parent process, destination reputation, certificate information, DNS history, and any files or registry changes created around the same time. HTTPS alone is common and does not imply maliciousness, while RAM capacity and DHCP use are irrelevant. Correlating rare-destination behavior with endpoint execution context substantially improves confidence compared with relying only on domain age or reputation.<\/span><\/p>\n<p><b>Question 184.<\/b><\/p>\n<p><b>Which threat-hunting technique focuses on identifying unusual behavior even when no known malicious indicator is available?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hash-only matching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static blacklist comparison<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Signature validation only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Behavioral hypothesis-driven hunting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral hypothesis-driven hunting begins with an assumption about how an attacker might behave and searches telemetry for evidence supporting that hypothesis. For example, a hunter might search for Office applications spawning script interpreters, unusual remote service creation, or abnormal use of privileged accounts. This approach can detect previously unknown threats that do not yet have known hashes, domains, or IP addresses. Static indicators remain useful, but they are easier for attackers to change. Behavioral hunting depends on quality telemetry, strong knowledge of normal activity, and careful validation because legitimate administrative behavior can resemble attacker techniques.<\/span><\/p>\n<p><b>Question 185.<\/b><\/p>\n<p><b>Which security control is most useful for identifying the specific executable responsible for a suspicious outbound connection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint detection and response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> VLAN trunking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response platforms can associate network connections with the exact process, file path, hash, command line, user account, and parent process that generated them. This allows analysts to distinguish between legitimate application traffic and malware communication. DHCP, NAT, and VLAN information may help with network attribution but generally cannot identify the local process responsible for a connection. EDR data is especially valuable when paired with firewall, proxy, or NetFlow telemetry. Together, these sources show both what communicated externally and which process initiated the communication, enabling more confident analysis and faster containment decisions.<\/span><\/p>\n<p><b>Question 186.<\/b><\/p>\n<p><b>An analyst observes repeated outbound connections to the same external destination, but the intervals vary randomly between 30 and 90 seconds. Why might an attacker use this behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To improve DNS resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To make beaconing patterns harder to detect<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To speed up DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To reduce file-system fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers may introduce timing variation, often called jitter, into command-and-control beaconing so that connections do not occur at perfectly predictable intervals. Fixed periodicity can be easier for statistical or behavioral detections to identify. Randomizing the interval helps malicious traffic blend into ordinary network activity. Analysts can still detect jittered beaconing by examining destination rarity, process identity, long-term connection patterns, byte counts, and historical baselines. Legitimate software can also use variable retry intervals, so timing alone is not enough. Combining endpoint and network context is critical for distinguishing malicious beaconing from normal automated traffic.<\/span><\/p>\n<p><b>Question 187.<\/b><\/p>\n<p><b>Which type of log would best help determine whether a malicious user successfully elevated privileges on a Windows system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Windows security and endpoint telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer queue history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> UPS battery logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor firmware information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows security logs and endpoint telemetry can provide evidence of privilege changes, privileged logons, token use, process execution, service creation, and other actions associated with privilege escalation. Analysts should examine the account involved, parent and child processes, command-line arguments, resulting security context, and whether suspicious activity followed the elevation. Printer and hardware logs do not provide relevant security context. Privilege escalation is especially important because it can allow an attacker to disable controls, access credentials, modify system settings, and move laterally. Analysts should also determine whether escalation exploited a vulnerability, misconfiguration, or stolen administrative credential.<\/span><\/p>\n<p><b>Question 188.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic is most closely associated with an attacker attempting to gain higher-level permissions after initial compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Privilege Escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privilege Escalation covers techniques adversaries use to obtain higher levels of permission, such as moving from a standard user context to administrator or SYSTEM privileges. This may involve exploiting vulnerabilities, abusing services, misconfigurations, token manipulation, or stolen credentials. Collection focuses on gathering data, Reconnaissance concerns information gathering, and Exfiltration covers data removal. Successful privilege escalation can significantly increase attacker capability because higher privileges may enable security control tampering, credential theft, persistence, and lateral movement. Mapping activity to ATT&amp;CK helps analysts understand the attacker\u2019s progression and identify where defensive controls may need improvement.<\/span><\/p>\n<p><b>Question 189.<\/b><\/p>\n<p><b>A SOC analyst detects a newly created local administrator account on a workstation shortly after suspicious PowerShell execution. Which attacker objective does this most directly support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence or privilege retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating a new local administrator account can provide persistence and privileged access even if the original compromise path is removed. The analyst should determine which process created the account, whether it has logged in, whether similar accounts exist on other hosts, and whether group membership or remote-access permissions were changed. Legitimate administrators can create accounts for valid reasons, so the timing and process context are important. If the account is malicious, incident response should include disabling or removing it, investigating the source credentials, and searching for related account-creation activity across the environment.<\/span><\/p>\n<p><b>Question 190.<\/b><\/p>\n<p><b>Which network behavior most strongly suggests internal reconnaissance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One host contacting its configured DNS server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> One endpoint probing many internal hosts and ports in a short time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A server performing its scheduled backup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A workstation synchronizing time with an NTP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Probing many internal hosts and ports in a short period is characteristic of network reconnaissance or scanning. Attackers often perform this activity after compromising a system to identify reachable services, administrative interfaces, databases, and potential lateral-movement targets. Legitimate vulnerability scanners and management systems may generate similar traffic, so analysts should identify the source process, user, device role, and expected scanning schedule. DNS and NTP activity are normal infrastructure functions, while a scheduled backup typically follows established communication patterns. NetFlow, firewall logs, EDR telemetry, and asset context can help distinguish malicious scanning from authorized activity.<\/span><\/p>\n<p><b>Question 191.<\/b><\/p>\n<p><b>Which security source is best suited to identifying large-scale port-scanning behavior across many network segments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NetFlow or network analytics telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Office document metadata<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Email signature settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and network analytics platforms provide broad visibility into source and destination addresses, ports, connection counts, protocols, and timing. These characteristics make them well suited to identifying scanning activity across multiple network segments. Analysts can look for one host generating a high number of short connections to many destinations or ports. Endpoint telemetry can then reveal which process generated the scan. Office metadata and firmware settings do not provide useful network behavior data. Broad network telemetry is especially valuable when the scanning system is not fully managed by endpoint security or when analysts need to understand activity across a large environment.<\/span><\/p>\n<p><b>Question 192.<\/b><\/p>\n<p><b>An analyst sees a process reading thousands of documents from multiple network shares and then creating one large archive. Which MITRE ATT&amp;CK tactic is most closely represented by the first part of this behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Initial Access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Defense Evasion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reading large numbers of documents from multiple network shares is consistent with Collection because the attacker appears to be gathering information of interest before further processing or transfer. Creating an archive may represent staging and preparation for exfiltration. Persistence focuses on maintaining access, Initial Access concerns gaining the initial foothold, and Defense Evasion involves avoiding detection. Analysts should inspect the user account, source process, file-access patterns, archive location, and any subsequent network transfer. Legitimate backup or indexing software can produce similar behavior, so baseline and application context are essential for accurate classification.<\/span><\/p>\n<p><b>Question 193.<\/b><\/p>\n<p><b>Which evidence would best confirm that a suspicious archive was actually transferred outside the organization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Outbound proxy, firewall, or flow records showing a matching transfer at the same time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The archive&#8217;s filename<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The user&#8217;s desktop background<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The destination workstation&#8217;s monitor type<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Outbound network telemetry can confirm that a transfer occurred and provide destination, timing, byte count, protocol, and source information. If the size and timing of the outbound session closely match the creation of a suspicious archive, the evidence becomes stronger. Proxy or secure web gateway logs may also reveal the specific cloud service or URL used. Endpoint telemetry can identify the process responsible for the upload. A filename alone does not prove that data left the organization. Correlating host and network evidence is the most reliable way to confirm whether staged data was actually exfiltrated.<\/span><\/p>\n<p><b>Question 194.<\/b><\/p>\n<p><b>Which evidence-preservation practice is most appropriate when a potentially compromised system may be needed for forensic investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete suspicious files before collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reboot the system repeatedly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Document actions and preserve evidence according to established procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted user activity to continue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Evidence preservation requires careful documentation and minimizing unnecessary changes to the system. Depending on the incident, investigators may capture volatile memory, collect logs, image storage, record hashes, and maintain chain of custody. Deleting files or repeatedly rebooting can destroy valuable evidence, while unrestricted user activity may alter system state or allow the compromise to continue. The exact collection order should follow organizational policy and consider the balance between containment and forensic value. Good evidence handling makes later conclusions more reliable and supports legal, regulatory, or disciplinary processes when necessary.<\/span><\/p>\n<p><b>Question 195.<\/b><\/p>\n<p><b>Which action best demonstrates that a forensic image remains unchanged during an investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recalculate and compare its cryptographic hash<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rename the image file<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store it on a different desktop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Compress it using another utility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash provides a content-based integrity value. If the hash calculated later matches the value recorded when the forensic image was acquired, investigators have strong evidence that the image has not changed. Renaming or moving a file does not validate integrity, while changing its representation through compression may produce a different file structure. Hash verification should be combined with controlled storage and chain-of-custody documentation. Investigators generally analyze validated copies while preserving original evidence. Any unexpected mismatch should be investigated because it may indicate alteration, corruption, or an acquisition problem.<\/span><\/p>\n<p><b>Question 196.<\/b><\/p>\n<p><b>Which forensic control helps prevent an acquisition workstation from modifying the original storage device?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network IDS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VPN concentrator<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Proxy server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Write blocker<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A write blocker prevents writes to the source media during forensic acquisition. This protects file-system metadata, timestamps, and other evidence from accidental modification by the analyst&#8217;s operating system or forensic tools. Hardware write blockers are common, although validated software-based approaches can also be used. Network IDS, VPN concentrators, and proxies serve different security functions and do not protect storage evidence from writes. Using a write blocker should be part of a broader forensic process that includes hashing, chain-of-custody documentation, secure storage, and analysis on verified copies rather than the original device.<\/span><\/p>\n<p><b>Question 197.<\/b><\/p>\n<p><b>A compromised endpoint is actively communicating with multiple internal hosts and a known malicious server. What should the incident-response team do first after obtaining any immediately required volatile evidence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Contain and isolate the endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Wait until the next scheduled maintenance window<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all investigation logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable the SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Once immediately required volatile evidence has been collected, containment should occur quickly to reduce further command-and-control communication, lateral movement, or data exfiltration. Isolation may be performed through EDR network containment, firewall controls, switch changes, or physical disconnection depending on policy. Waiting unnecessarily increases risk, while deleting logs or disabling monitoring removes essential visibility. After containment, analysts can continue scoping affected systems, investigating persistence, identifying compromised credentials, and preparing eradication. The response should be documented so actions and timing are clear for later review.<\/span><\/p>\n<p><b>Question 198.<\/b><\/p>\n<p><b>Which action is most appropriate during eradication after malicious activity has been contained?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reconnect affected systems immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove malware, persistence, compromised credentials, and exploited weaknesses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable monitoring to reduce noise<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes the attacker&#8217;s remaining footholds and addresses the root cause of compromise. This can include removing malicious files, deleting persistence mechanisms, resetting compromised credentials, revoking tokens, patching vulnerabilities, and removing unauthorized tools. A system should not return to production simply because network isolation stopped the immediate threat. If the environment is heavily compromised, rebuilding from trusted images may provide stronger assurance than manual cleanup. Monitoring should remain active because it can help verify whether eradication was complete. Incident records should also be preserved so the organization can learn from the response.<\/span><\/p>\n<p><b>Question 199.<\/b><\/p>\n<p><b>Which action best represents recovery after eradication is complete?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restore systems to production in a controlled manner and monitor closely for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable endpoint protection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all security logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore compromised accounts because malware was deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery returns systems and services to normal operation after the active threat and root cause have been addressed. Systems should be validated, patched, protected, and restored from trusted sources when required. Compromised accounts and credentials must also be handled before reconnection. Once systems return to production, enhanced monitoring should continue for a period so recurrence can be detected quickly. Disabling protection or deleting logs would weaken the environment. Recovery is not merely technical restoration; it is a controlled process that balances business continuity with confidence that attacker access has been removed.<\/span><\/p>\n<p><b>Question 200.<\/b><\/p>\n<p><b>A post-incident review finds that analysts had sufficient telemetry but lacked a consistent way to correlate identity, endpoint, and network activity. Which improvement would provide the greatest benefit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce the number of collected log sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Stop retaining historical data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Build and test correlation rules and investigation playbooks across the available telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable behavioral analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If the necessary telemetry already exists, the next improvement should focus on using it more effectively. Correlation rules can connect suspicious identity events, endpoint processes, DNS activity, and network communication into a coherent attack sequence. Investigation playbooks can then guide analysts through enrichment, validation, scoping, containment, and escalation steps. Reducing telemetry or disabling behavioral analytics would make detection weaker. The organization should test new correlations against historical incidents and representative benign activity to balance detection coverage with false-positive control. Strong correlation and repeatable workflows can significantly reduce detection and response time.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 181. A SOC analyst notices that a user account successfully authenticated to a critical server from a host that has never previously accessed that server. Which factor would most strongly increase the likelihood of compromise? The source host was previously associated [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23784"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23784"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23784\/revisions"}],"predecessor-version":[{"id":23785,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23784\/revisions\/23785"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}