{"id":23792,"date":"2026-09-28T09:59:25","date_gmt":"2026-09-28T09:59:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23792"},"modified":"2026-09-28T09:59:25","modified_gmt":"2026-09-28T09:59:25","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 261.<\/b><\/p>\n<p><b>A SOC analyst sees a standard user account authenticate successfully to several database servers within two minutes. Which factor should be checked first to determine whether this is lateral movement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the account normally accesses those systems and what activity followed the logins<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether the servers use SSD storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the switches support PoE<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the user recently changed the desktop background<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The analyst should first compare the activity with the user&#8217;s normal behavior and review what occurred immediately after authentication. A standard user suddenly accessing several database servers may indicate stolen credentials or lateral movement, particularly if the account has no legitimate business reason to reach those systems. Authentication logs, EDR telemetry, privilege information, process creation, and network activity can help establish whether the logins were malicious. Hardware and desktop settings are irrelevant. A successful login alone is not enough to prove compromise, so behavioral context and subsequent actions are essential for an accurate conclusion.<\/span><\/p>\n<p><b>Question 262.<\/b><\/p>\n<p><b>Which telemetry source would best help determine which command was executed immediately after a remote administrator login to a Windows host?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint process and command-line telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer spooler events<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Building access logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process and command-line telemetry provides direct evidence of what executed after authentication. It can reveal executable paths, parent and child processes, command-line arguments, user context, hashes, and network connections. This allows the analyst to determine whether the login was followed by legitimate administration or suspicious remote execution. DHCP logs may identify a device at a particular time, but they do not reveal commands. Printer and physical-access logs are also unrelated. Analysts should correlate process telemetry with authentication timestamps to build a reliable sequence of events.<\/span><\/p>\n<p><b>Question 263.<\/b><\/p>\n<p><b>An analyst identifies <\/b><b>certutil.exe<\/b><b> downloading a file from an external URL. Which security concept best describes the potential misuse?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deduplication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Living off the land<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backup rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Living-off-the-land techniques involve abusing legitimate system utilities for malicious purposes. <\/span><span style=\"font-weight: 400;\">certutil.exe<\/span><span style=\"font-weight: 400;\"> is a legitimate Windows utility, but attackers may misuse it to download or process files. Because the binary itself may be trusted and signed, detections should focus on how it is used, including command-line arguments, destination URLs, parent processes, user context, and subsequent execution. The analyst should not assume that every use of <\/span><span style=\"font-weight: 400;\">certutil.exe<\/span><span style=\"font-weight: 400;\"> is malicious, but unusual network activity associated with it deserves investigation. Behavioral monitoring is especially useful for identifying this kind of trusted-tool abuse.<\/span><\/p>\n<p><b>Question 264.<\/b><\/p>\n<p><b>Which approach is best for detecting malicious use of legitimate signed system utilities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block every signed executable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow all Microsoft-signed binaries without monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Search only for malicious hashes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detect unusual command lines, parent-child relationships, users, and network behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legitimate signed binaries are frequently abused by attackers, so trust should not be based only on digital signatures. Behavioral detections can identify suspicious command-line options, unusual parent processes, execution by unexpected users, access to rare destinations, or abnormal file activity. Blocking all signed utilities would severely disrupt operations, while ignoring them creates a major detection gap. Hash-based detection is also inadequate because the utility itself may be legitimate. Strong detection strategies combine process context, identity, endpoint, and network telemetry to recognize misuse while allowing legitimate administration.<\/span><\/p>\n<p><b>Question 265.<\/b><\/p>\n<p><b>A workstation begins contacting a newly registered domain from a process located in a user profile&#8217;s temporary directory. Which factor most increases suspicion?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The executable is unsigned and was created moments before the first connection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The workstation has a static IP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The domain uses HTTPS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The user is connected through Ethernet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unsigned executable appearing in a temporary directory immediately before contacting a newly registered domain is a strong combination of suspicious indicators. Analysts should review the parent process, file hash, creation source, command line, digital signature, persistence activity, and destination reputation. HTTPS is common for both legitimate and malicious communication and should not be treated as proof of safety or compromise. Static addressing and Ethernet connectivity are normal network characteristics. Multiple related anomalies provide much stronger evidence than a single indicator viewed in isolation.<\/span><\/p>\n<p><b>Question 266.<\/b><\/p>\n<p><b>Which threat-intelligence property describes how trustworthy a source or indicator is believed to be?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Throughput<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Confidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Latency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidence represents how strongly an intelligence provider or analyst believes an indicator or assessment is accurate. High-confidence intelligence may justify more aggressive automated action, while lower-confidence data may be better suited for enrichment or manual investigation. Confidence should be considered alongside freshness, source reliability, context, and potential impact. No threat feed is perfect, and indicators can become stale or be incorrectly attributed. Treating every indicator as equally reliable can create false positives and unnecessary blocking. Mature threat-intelligence programs use confidence scoring to support better operational decisions.<\/span><\/p>\n<p><b>Question 267.<\/b><\/p>\n<p><b>Which threat-intelligence source would best help determine whether a suspicious domain previously resolved to several malicious IP addresses?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Passive DNS data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows registry data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network interface settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passive DNS data records historical relationships between domain names and IP addresses. Analysts can use it to determine whether a suspicious domain has moved between infrastructure providers or previously resolved to addresses associated with malware campaigns. This information can also reveal related domains using the same infrastructure. Because shared hosting can create innocent associations, passive DNS findings should be combined with registration data, certificate information, timestamps, reputation, and other threat intelligence. Registry and printer information do not provide external domain-to-IP history.<\/span><\/p>\n<p><b>Question 268.<\/b><\/p>\n<p><b>Which network pattern most strongly suggests possible command-and-control traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One approved software update each month<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A user accessing an internal portal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A DHCP request at system startup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Small repeated outbound connections from the same process to a rare destination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Small repeated outbound connections from a consistent process to a rare external destination can indicate command-and-control beaconing. Malware often checks in periodically to receive commands or report status. Analysts should examine timing, jitter, byte counts, destination reputation, TLS certificate data, process path, and whether other hosts show similar patterns. Legitimate monitoring and update applications can also produce periodic traffic, so context is necessary. DHCP and ordinary user browsing do not typically create this recurring process-to-destination pattern.<\/span><\/p>\n<p><b>Question 269.<\/b><\/p>\n<p><b>A security analyst sees command-and-control connections every few minutes, but the intervals are not identical. What technique may the malware be using?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Jitter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data normalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> File carving<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Port mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jitter refers to deliberate variation in the timing of command-and-control callbacks. Rather than communicating at an exact interval, malware can randomize delays to make periodic behavior less obvious to simple detections. Analysts may still identify the pattern through long-term traffic analysis, destination rarity, process attribution, and statistical timing characteristics. Jitter does not make the activity invisible; it merely makes highly regular beacon detection more difficult. Data normalization, file carving, and port mirroring serve entirely different purposes.<\/span><\/p>\n<p><b>Question 270.<\/b><\/p>\n<p><b>Which telemetry would best help determine whether a suspicious external connection transferred a large amount of data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BIOS event logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NetFlow or firewall session records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Badge access logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Keyboard configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and firewall session records can provide byte counts, packet counts, source and destination addresses, ports, protocols, timestamps, and duration. These fields help analysts determine whether a suspicious session involved a large transfer that could represent exfiltration. Flow data is efficient for broad visibility but normally does not show exact payload content. Endpoint, proxy, DLP, or packet data may be needed for deeper analysis. Physical and hardware configuration sources cannot provide meaningful network-transfer measurements.<\/span><\/p>\n<p><b>Question 271.<\/b><\/p>\n<p><b>A compromised endpoint reads thousands of sensitive files and creates a password-protected archive. Which attacker activity is most likely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection and staging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS recursion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> NTP synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk access to sensitive files followed by creation of a password-protected archive strongly suggests collection and staging. Attackers often gather data and consolidate it into archives before exfiltration to simplify transfer and reduce file-level visibility. Analysts should inspect which files were accessed, which process created the archive, the user account involved, storage location, and any subsequent external connections. Legitimate backup applications can produce similar behavior, so business context remains important. DNS, DHCP, and NTP do not explain this sequence.<\/span><\/p>\n<p><b>Question 272.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic best describes gathering sensitive documents for later theft?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Defense Evasion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Collection covers adversary techniques used to gather information before it is exfiltrated or otherwise used. This may include documents, email, browser data, databases, screenshots, or data from shared drives. Collection often appears shortly before staging or exfiltration. Reconnaissance focuses on learning about targets, Persistence maintains access, and Defense Evasion attempts to avoid detection. Mapping observed behavior to ATT&amp;CK helps analysts describe the attack consistently and identify missing detection coverage.<\/span><\/p>\n<p><b>Question 273.<\/b><\/p>\n<p><b>Which evidence most strongly confirms that a staged archive was transferred outside the organization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Outbound traffic matching the archive&#8217;s size and creation time to an unusual external destination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The archive has a <\/span><span style=\"font-weight: 400;\">.7z<\/span><span style=\"font-weight: 400;\"> extension<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The file owner has read permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The workstation uses Windows<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Archive creation alone indicates possible staging but does not prove exfiltration. Outbound traffic that closely matches the archive&#8217;s creation time and approximate size, especially to a rare or suspicious external destination, provides much stronger evidence that the data left the organization. Analysts should also identify the process responsible for the transfer and review proxy, firewall, DLP, or cloud logs. File extension and operating system do not establish exfiltration. Correlation between host and network telemetry is essential for reaching a defensible conclusion.<\/span><\/p>\n<p><b>Question 274.<\/b><\/p>\n<p><b>Which source would best help an analyst identify an upload of sensitive data to an external web application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer queue logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Secure web gateway or proxy telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure web gateway or proxy telemetry can provide information about web destinations, URLs, users, source IPs, timestamps, request methods, and transferred bytes. Depending on TLS inspection and application controls, it may also identify file uploads or cloud applications. Analysts should correlate this with endpoint telemetry showing file access or archive creation. If traffic is encrypted and not decrypted, metadata can still support the investigation. Printer, BIOS, and monitor information do not provide relevant application-layer web visibility.<\/span><\/p>\n<p><b>Question 275.<\/b><\/p>\n<p><b>Which evidence source is most volatile and may disappear when a live system is powered off?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAM contents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Archived backup media<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printed documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Asset inventory records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RAM contains highly volatile information such as active processes, network connections, injected code, encryption keys, credentials, and command history. Much of this information disappears when a system loses power. If volatile artifacts are important to an investigation and policy allows it, memory should be acquired before shutdown. Investigators must balance this with containment because a live compromised host may continue causing harm. Persistent records such as backups and inventory data are less time-sensitive. Memory images should be documented, hashed, and protected appropriately.<\/span><\/p>\n<p><b>Question 276.<\/b><\/p>\n<p><b>Which forensic tool is used to prevent accidental modification of source storage during acquisition?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network tap<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Packet broker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Load balancer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Write blocker<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A write blocker prevents the acquisition workstation from writing data to the original storage media. This helps preserve file-system structures, timestamps, metadata, and deleted-file artifacts. It is commonly used when creating forensic images of evidence devices. A write blocker does not replace cryptographic hashing, secure storage, or chain-of-custody documentation. Network taps and packet brokers support network monitoring, while load balancers distribute traffic. Analysts should generally perform examination on verified forensic copies rather than original evidence.<\/span><\/p>\n<p><b>Question 277.<\/b><\/p>\n<p><b>A compromised endpoint is actively propagating malware to neighboring systems. Which response phase should be prioritized immediately?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Containment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Lessons learned<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Recovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Preparation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment is the priority when malware is actively spreading because the objective is to limit additional systems from becoming compromised. Actions may include EDR isolation, firewall restrictions, account controls, switch changes, or physical network disconnection. If important volatile evidence can be safely collected first, responders may preserve it before complete isolation, depending on policy and risk. Lessons learned and recovery occur later. Containment does not remove the root cause, so it must be followed by scoping and eradication.<\/span><\/p>\n<p><b>Question 278.<\/b><\/p>\n<p><b>Which activity belongs primarily to eradication after containment is complete?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reconnect affected systems immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove malware, persistence, compromised credentials, and exploited vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete incident documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes the attacker&#8217;s footholds and addresses the causes that enabled compromise. Activities can include deleting malware, removing malicious services or scheduled tasks, resetting stolen credentials, revoking tokens, patching exploited vulnerabilities, and rebuilding systems when necessary. Containment alone only limits ongoing activity. Recovery should not begin until the response team has reasonable confidence that the threat has been removed. Deleting records or disabling monitoring would reduce visibility and weaken the response.<\/span><\/p>\n<p><b>Question 279.<\/b><\/p>\n<p><b>Which action is most appropriate during recovery after a compromised server has been rebuilt?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate security controls, restore service, and monitor closely for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restore known malicious persistence for testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reuse compromised credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery involves safely returning systems to production after eradication. Before reconnection, responders should verify patching, security configuration, endpoint protection, credentials, application functionality, and absence of known compromise indicators. Monitoring should be increased temporarily because renewed suspicious activity may indicate incomplete eradication or another attacker foothold. Logging and security controls should remain enabled. Reusing compromised credentials or malicious artifacts would undermine the response and could allow immediate re-entry.<\/span><\/p>\n<p><b>Question 280.<\/b><\/p>\n<p><b>A post-incident review reveals that analysts could not quickly determine which assets were business-critical, slowing prioritization. What improvement would most directly address this problem?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce endpoint telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable severity scoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Integrate accurate asset criticality and ownership data into SOC alerts and workflows<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shorten all log-retention periods<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset criticality and ownership information help analysts evaluate the business impact of an alert. A suspicious event on a domain controller, payment system, or sensitive database usually deserves higher priority than the same event on a low-impact test system. Integrating this context into SIEM alerts and investigation workflows reduces manual lookup and improves consistent triage. The asset inventory should be accurate, current, and tied to responsible owners. Reducing telemetry or severity information would make prioritization harder. Post-incident lessons should therefore improve both technical detections and the contextual data analysts need to make fast, informed decisions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 261. A SOC analyst sees a standard user account authenticate successfully to several database servers within two minutes. Which factor should be checked first to determine whether this is lateral movement? Whether the account normally accesses those systems and what activity [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23792"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23792"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23792\/revisions"}],"predecessor-version":[{"id":23793,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23792\/revisions\/23793"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23792"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23792"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23792"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}