{"id":23790,"date":"2026-09-28T09:59:08","date_gmt":"2026-09-28T09:59:08","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23790"},"modified":"2026-09-28T09:59:08","modified_gmt":"2026-09-28T09:59:08","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 241.<\/b><\/p>\n<p><b>A SOC analyst observes a compromised endpoint attempting authentication to multiple internal servers using the same account. Which activity should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Potential lateral movement using stolen credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer spooler status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP lease renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor firmware version<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated authentication from a known compromised endpoint to multiple internal servers strongly suggests possible lateral movement. The analyst should review the account used, destination systems, authentication methods, logon types, privilege level, timestamps, and activity that followed each successful login. Endpoint telemetry from the source host can help determine whether malware, a remote administration tool, or a script initiated the connections. Authentication behavior should also be compared with historical baselines to distinguish legitimate administration from compromise. Printer, DHCP, and display information are unrelated to the security question. If the account is confirmed compromised, containment may require host isolation, session revocation, credential reset, and broader scoping for additional affected systems.<\/span><\/p>\n<p><b>Question 242.<\/b><\/p>\n<p><b>Which log source is most useful for identifying whether a remote Windows login was followed by suspicious process execution on the destination host?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Badge access records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint process telemetry on the destination system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer queue history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> UPS event logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process telemetry on the destination host can reveal what executed immediately after a remote login, including process names, parent-child relationships, command-line arguments, user context, file paths, and network connections. This helps determine whether the login was followed by legitimate administration or suspicious remote execution. Authentication logs provide important identity context, but process telemetry shows what the account actually did after access was established. Physical access, printer, and UPS logs do not provide this visibility. Analysts should correlate source and destination telemetry to reconstruct the sequence and determine whether the same behavior occurred elsewhere in the environment.<\/span><\/p>\n<p><b>Question 243.<\/b><\/p>\n<p><b>An analyst notices that <\/b><b>wmic.exe<\/b><b> is being used remotely from a workstation that has never performed administrative tasks before. Which concept best describes the potential attacker behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data staging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical intrusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Living off the land<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backup validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Living-off-the-land behavior involves abusing legitimate, built-in tools for malicious purposes. Utilities such as WMI-related tools can be used by administrators for legitimate management, but attackers may also use them for remote execution, discovery, or lateral movement because they are trusted and already present. The analyst should review command-line arguments, user context, source and destination hosts, authentication events, and any child processes or network activity that followed. The fact that the source workstation normally performs no administrative activity increases suspicion. Behavioral context is essential because the tool itself is not inherently malicious.<\/span><\/p>\n<p><b>Question 244.<\/b><\/p>\n<p><b>Which detection approach is most effective for identifying malicious use of built-in system utilities such as PowerShell, WMI, or command shells?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block all signed binaries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore built-in tools because they are trusted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Search only for malware hashes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Analyze command lines, parent processes, user context, and resulting behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted system utilities are frequently used legitimately, so neither blanket blocking nor unconditional trust is appropriate. Behavioral analysis is more effective because it examines how the tool is being used. Suspicious command-line arguments, unusual parent-child relationships, unexpected users, rare destinations, encoded content, or abnormal remote execution patterns can reveal abuse. Hash-based detection alone is inadequate because the tool may be a legitimate operating-system binary. The strongest detections combine process behavior with endpoint, identity, and network telemetry. This approach helps identify attacker use of legitimate tools while reducing false positives from normal administration.<\/span><\/p>\n<p><b>Question 245.<\/b><\/p>\n<p><b>A workstation begins contacting a newly registered domain immediately after a suspicious script executes. Which additional artifact would provide the strongest evidence that the script initiated the connection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EDR process-to-network telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EDR process-to-network telemetry can directly associate an outbound connection with the process that generated it. This allows the analyst to determine whether the suspicious script interpreter or a child process contacted the newly registered domain. The analyst can also review the process path, command line, hash, parent process, user context, and related file activity. DHCP information may help map an IP address to a device but does not identify the initiating process. Printer and display data are unrelated. Correlating process and network activity is especially valuable when investigating command-and-control or malware-delivery behavior.<\/span><\/p>\n<p><b>Question 246.<\/b><\/p>\n<p><b>Which threat-intelligence attribute should an analyst consider when deciding whether to block a newly reported malicious domain automatically?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The domain name length only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Confidence, freshness, and source reliability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the domain contains numbers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the domain resolves quickly<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence indicators vary in quality and lifespan. Before automatically blocking a domain, analysts should evaluate how recently malicious activity was observed, how reliable the source is, and the confidence assigned to the indicator. Domains can change ownership, infrastructure can be repurposed, and low-confidence intelligence can create false positives. Domain length, use of numbers, and DNS response speed do not determine maliciousness. High-confidence, fresh indicators tied to active campaigns may justify immediate blocking, while lower-confidence intelligence may be more appropriate for alert enrichment or investigation. Context should always guide automation decisions.<\/span><\/p>\n<p><b>Question 247.<\/b><\/p>\n<p><b>A security analyst wants to identify whether a suspicious domain shares infrastructure with other known malicious domains. Which source would be most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Passive DNS intelligence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> BIOS inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> File-system permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passive DNS intelligence can reveal historical relationships between domains and IP addresses, making it useful for infrastructure analysis. If several suspicious domains resolved to the same IP addresses or shared similar hosting patterns, analysts may identify broader malicious infrastructure or campaign relationships. Passive DNS should be interpreted carefully because shared hosting and cloud platforms can place unrelated domains on the same infrastructure. Additional context such as registration data, certificate information, threat reputation, and timestamps improves confidence. BIOS, printer, and file-permission data do not provide external DNS infrastructure relationships.<\/span><\/p>\n<p><b>Question 248.<\/b><\/p>\n<p><b>Which network pattern would most strongly suggest command-and-control beaconing rather than ordinary interactive browsing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One large web download from an approved vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Repeated small connections at similar intervals to a rare external destination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A user opening several internal web pages<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A routine software update<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command-and-control malware often sends periodic small connections to check in with attacker infrastructure, receive commands, or report host status. Repeated communication to a rare external destination with similar timing and small payloads can therefore indicate beaconing. Legitimate software can behave similarly, so analysts should also review the responsible process, domain reputation, certificate data, timing jitter, byte counts, and whether other hosts show the same pattern. Interactive browsing is typically more irregular and user-driven. Correlating network periodicity with endpoint process data is one of the best ways to distinguish malicious beaconing from legitimate automated traffic.<\/span><\/p>\n<p><b>Question 249.<\/b><\/p>\n<p><b>An analyst sees beacon-like traffic with intervals that vary randomly between 5 and 10 minutes. Why might malware use this pattern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To make periodic communication less obvious to simple detections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To improve DHCP reliability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To increase DNS cache lifetime<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To speed up disk access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Malware may use jitter, or randomized timing variation, to avoid detections that look for perfectly regular periodic connections. Instead of contacting command-and-control infrastructure exactly every five minutes, the malware may choose a random delay within a range. This makes the pattern blend more naturally into ordinary network traffic. Analysts can still detect this behavior by examining long-term destination rarity, process identity, repeated connections, similar byte counts, and statistical timing characteristics. DHCP, DNS cache behavior, and disk performance are unrelated to beacon timing. Strong behavioral analytics are needed to detect attackers who intentionally reduce obvious periodicity.<\/span><\/p>\n<p><b>Question 250.<\/b><\/p>\n<p><b>Which source would be most useful for determining the total amount of data transferred from an internal system to an external IP address over a period of several hours?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical badge logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NetFlow or firewall traffic records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS event logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer queue data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and firewall traffic records can provide byte counts, packet counts, source and destination addresses, protocols, ports, session duration, and timestamps. This makes them useful for measuring outbound data volume and identifying possible exfiltration. Analysts can compare the observed transfer volume with historical baselines and the host&#8217;s normal role. A large transfer is not automatically malicious because backups, cloud synchronization, and software distribution can be legitimate. Additional context from endpoint telemetry, proxy data, and data-classification systems may be required. Physical, BIOS, and printer information do not provide network transfer volume.<\/span><\/p>\n<p><b>Question 251.<\/b><\/p>\n<p><b>An endpoint accesses thousands of sensitive files in a short time and then creates a compressed archive. Which attacker activity is most likely occurring?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data collection and staging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network time synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk access to sensitive files followed by creation of a compressed archive is consistent with collection and staging. Attackers often gather documents from multiple locations and package them into a single archive before exfiltration. This reduces the number of files that must be transferred and may make the operation less obvious. Analysts should examine the process that created the archive, the account involved, file types, archive location, encryption settings, and any subsequent outbound network activity. Legitimate backup or archival software can produce similar behavior, so business context is important. DNS, DHCP, and NTP do not explain this sequence.<\/span><\/p>\n<p><b>Question 252.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic best describes gathering sensitive files from multiple systems before transferring them externally?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Defense Evasion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Resource Development<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Collection describes adversary techniques used to gather information of interest before it is transferred, analyzed, or otherwise used. Attackers may collect documents, browser data, email, screenshots, database information, or files from shared storage. This activity often precedes staging and exfiltration. Persistence focuses on maintaining access, Defense Evasion is about avoiding detection, and Resource Development relates to preparing infrastructure and capabilities. Analysts should look for bulk file access, unusual archive creation, temporary staging directories, and outbound transfers. ATT&amp;CK mapping helps organize observations into a broader understanding of the attack lifecycle.<\/span><\/p>\n<p><b>Question 253.<\/b><\/p>\n<p><b>Which evidence would most strongly indicate that collected data was actually exfiltrated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A matching outbound transfer to an unusual external destination shortly after archive creation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The archive has a <\/span><span style=\"font-weight: 400;\">.zip<\/span><span style=\"font-weight: 400;\"> extension<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The user has write permissions to the folder<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The endpoint is connected to Ethernet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Archive creation suggests staging, but it does not prove the data left the organization. A large outbound transfer to an unusual destination shortly afterward provides much stronger evidence of exfiltration. Analysts should correlate transfer size, timing, process identity, destination reputation, protocol, and user context. If possible, secure web gateway, firewall, or DLP data may show the specific service or file involved. A <\/span><span style=\"font-weight: 400;\">.zip<\/span><span style=\"font-weight: 400;\"> extension or folder permissions do not establish that data was transmitted externally. Ethernet connectivity is normal and irrelevant. The strongest conclusions come from correlating host and network evidence into a clear sequence.<\/span><\/p>\n<p><b>Question 254.<\/b><\/p>\n<p><b>Which telemetry would best help determine whether an archive was uploaded to a cloud-storage service through a web browser?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network switch fan speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Secure web gateway or proxy logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP reservation details<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure web gateway or proxy logs can provide destination URLs, domains, usernames, client IP addresses, timestamps, request types, and byte counts. Depending on inspection capabilities, they may also identify upload actions or file-related details. Analysts should correlate the web activity with browser process telemetry and the time the archive was created. If TLS inspection is unavailable, metadata can still be useful in confirming a large session to a cloud-storage service. Switch, BIOS, and DHCP information do not reveal application-layer upload behavior. Endpoint and network evidence should be combined to establish whether the transfer was authorized.<\/span><\/p>\n<p><b>Question 255.<\/b><\/p>\n<p><b>Which forensic evidence should generally be acquired before shutting down a live compromised system when memory artifacts are important to the investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Volatile memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printed network diagrams<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Asset purchase records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware warranty information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Volatile memory can contain running processes, injected code, active network connections, encryption keys, command history, credentials, and other artifacts that may disappear when power is removed. If the investigation requires this information and organizational procedures permit it, memory should be collected before shutdown. The response team must still balance evidence preservation with containment because a live compromised host may continue causing damage. Persistent documents and administrative records can be collected later. The memory image should be documented, hashed, and protected according to evidence-handling procedures when forensic integrity is required.<\/span><\/p>\n<p><b>Question 256.<\/b><\/p>\n<p><b>Which forensic tool helps protect an original storage device from modification during imaging?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SIEM connector<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VPN gateway<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Proxy server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Write blocker<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A write blocker prevents writes to the source storage device during forensic acquisition. This helps preserve file-system metadata, timestamps, deleted-file structures, and other evidence. Hardware write blockers are commonly used, though validated software mechanisms may also be appropriate. A write blocker does not replace forensic imaging, cryptographic hashing, or chain-of-custody documentation; it simply reduces the risk of accidental modification. SIEM connectors, VPN gateways, and proxy servers have unrelated functions. Evidence should generally be analyzed from verified forensic copies while the original media is securely preserved.<\/span><\/p>\n<p><b>Question 257.<\/b><\/p>\n<p><b>A system is actively communicating with known command-and-control infrastructure. Which incident-response phase should focus on stopping that communication quickly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Containment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Lessons learned<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Recovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Preparation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment aims to limit the immediate impact of an incident and prevent additional attacker activity. Stopping command-and-control communication may involve isolating the endpoint, blocking malicious infrastructure, restricting compromised accounts, or segmenting affected systems. The exact method should follow organizational procedures and balance containment with evidence preservation. Recovery happens after eradication, lessons learned follows incident resolution, and preparation occurs before an incident. Quick containment can reduce data loss, lateral movement, and malware propagation, but it should be followed by thorough scoping and eradication rather than treated as the final solution.<\/span><\/p>\n<p><b>Question 258.<\/b><\/p>\n<p><b>Which action belongs primarily to the eradication phase?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitoring for recurrence after restoration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Removing malware, persistence, and compromised credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Writing the initial incident-response policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Conducting routine security awareness training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes the attacker&#8217;s footholds and addresses the root cause of compromise. This can include deleting malware, removing malicious services or scheduled tasks, resetting compromised credentials, revoking tokens, patching exploited vulnerabilities, and removing unauthorized accounts. Monitoring for recurrence is mainly associated with recovery, while policy creation and awareness training belong to preparation or general security operations. Eradication must be comprehensive. If only the visible malware is removed while stolen credentials or persistence remain active, the attacker may regain access. In severe cases, rebuilding systems from trusted images may provide stronger assurance.<\/span><\/p>\n<p><b>Question 259.<\/b><\/p>\n<p><b>Which action is most appropriate during recovery after eradication has been completed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Return validated systems to service and monitor closely for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable endpoint protection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all investigation records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Restore known malicious files for comparison<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery returns systems and services to normal operations after the active threat and its root causes have been addressed. Before reconnection, teams should verify patches, security controls, credentials, system configuration, and the absence of known malicious artifacts. Restored systems should be monitored closely because renewed command-and-control traffic or suspicious authentication may indicate incomplete eradication. Disabling security controls or restoring malware would undermine the response. Investigation records should remain available for audit, lessons learned, and future detection improvement. Recovery should balance business continuity with confidence that the environment is safe.<\/span><\/p>\n<p><b>Question 260.<\/b><\/p>\n<p><b>A post-incident review shows that analysts repeatedly had to perform the same manual searches across EDR, SIEM, DNS, and threat-intelligence systems. Which improvement would most directly reduce response time?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce telemetry sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shorten retention periods<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automate common enrichment and pivoting steps within the investigation workflow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable correlations involving multiple platforms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automating common enrichment and pivoting tasks can significantly reduce analyst workload and response time. A workflow can automatically collect endpoint details, user information, DNS history, domain reputation, related alerts, asset criticality, and recent authentication activity when an alert arrives. Analysts can then focus on judgment, scoping, and containment instead of repeatedly gathering the same context. High-impact actions can remain subject to human approval. Reducing telemetry or disabling cross-platform correlation would weaken visibility. Post-incident reviews should identify repetitive manual processes and convert them into tested, documented automation where doing so improves consistency without sacrificing control.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 241. A SOC analyst observes a compromised endpoint attempting authentication to multiple internal servers using the same account. Which activity should be investigated first? Potential lateral movement using stolen credentials 2. Printer spooler status 3. DHCP lease renewal 4. Monitor firmware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23790"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23790"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23790\/revisions"}],"predecessor-version":[{"id":23791,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23790\/revisions\/23791"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}