{"id":23794,"date":"2026-09-28T09:59:41","date_gmt":"2026-09-28T09:59:41","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23794"},"modified":"2026-09-28T09:59:41","modified_gmt":"2026-09-28T09:59:41","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 281.<\/b><\/p>\n<p><b>A SOC analyst sees a privileged account authenticate to several servers from a workstation that is normally used only for email and web browsing. Which interpretation is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The activity may indicate credential misuse or lateral movement and should be investigated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The behavior is automatically legitimate because the account is privileged<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The workstation should be ignored because it is not a server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The event is caused by normal DHCP activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A privileged account authenticating from a workstation that does not normally perform administrative activity is a meaningful behavioral anomaly. The analyst should review the source endpoint, account owner, MFA events, logon types, destination systems, and processes launched after authentication. Endpoint telemetry may reveal whether malware, PowerShell, a remote administration utility, or another process initiated the activity. Privileged status does not make unusual behavior inherently legitimate. In fact, privilege increases potential impact if credentials are compromised. Historical baselines, user role information, and source-device reputation should all contribute to prioritization and response decisions.<\/span><\/p>\n<p><b>Question 282.<\/b><\/p>\n<p><b>Which data source would best help determine whether the privileged account in the previous scenario launched remote commands after authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer server logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint process telemetry from the destination systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Wireless channel utilization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Badge-reader battery status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process telemetry on the destination systems can show what executed after the remote authentication, including process names, parent-child relationships, command lines, user context, file paths, and network behavior. This helps determine whether the activity was legitimate administration or unauthorized remote execution. Authentication logs provide identity context, but process telemetry explains what happened after access was granted. Printer, wireless channel, and badge-reader information do not provide relevant execution evidence. Analysts should correlate destination events with the source workstation timeline to reconstruct the complete sequence accurately.<\/span><\/p>\n<p><b>Question 283.<\/b><\/p>\n<p><b>An analyst observes <\/b><b>mshta.exe<\/b><b> launching a script retrieved from an external location. Which security concept best describes the potential attacker technique?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical access abuse<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Living off the land<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data deduplication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Living-off-the-land techniques abuse legitimate system utilities and trusted binaries to perform malicious actions. <\/span><span style=\"font-weight: 400;\">mshta.exe<\/span><span style=\"font-weight: 400;\"> is a legitimate Windows component, but attackers may misuse it to execute remote or local script content. Because the binary itself may be signed and trusted, static reputation alone may not identify malicious use. Analysts should inspect the command line, external URL, parent process, user context, subsequent child processes, file activity, and outbound connections. Behavioral detection is especially valuable for this class of activity because the distinction between legitimate and malicious use depends heavily on execution context.<\/span><\/p>\n<p><b>Question 284.<\/b><\/p>\n<p><b>Which strategy is most effective for detecting malicious use of <\/b><b>mshta.exe<\/b><b>, PowerShell, or other trusted Windows utilities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust all digitally signed executables automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all Windows administrative tools<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Search only for known malicious file hashes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detect suspicious command lines, execution chains, users, and network destinations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted Windows tools are frequently used for legitimate administration, but they can also be abused by attackers. Effective detection therefore focuses on context: suspicious command-line parameters, unusual parent processes, encoded scripts, unexpected users, rare destinations, or abnormal child processes. Trusting all signed binaries would create major blind spots, while disabling every administrative tool would disrupt normal operations. File-hash detection is also insufficient because the underlying utility may be a legitimate Microsoft binary. Behavioral analytics combined with identity and network context provide much stronger coverage.<\/span><\/p>\n<p><b>Question 285.<\/b><\/p>\n<p><b>A workstation contacts an unfamiliar external domain immediately after an Office application launches a script interpreter. Which investigative action provides the strongest next step?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Correlate the process tree with DNS, proxy, and network connection telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace the user&#8217;s keyboard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable DHCP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the user&#8217;s browsing history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The combination of an Office application launching a script interpreter and subsequent communication with an unfamiliar domain may indicate malicious document execution. Correlating the process tree with DNS, proxy, firewall, and endpoint network telemetry can establish whether the script or a child process generated the connection. The analyst should also inspect command-line arguments, downloaded files, persistence changes, and email-delivery context. Hardware replacement or DHCP changes do not address the incident. Deleting browsing history could also destroy useful evidence. Cross-source correlation helps turn isolated suspicious events into a coherent attack sequence.<\/span><\/p>\n<p><b>Question 286.<\/b><\/p>\n<p><b>Which threat-intelligence attribute is most important when deciding whether an IP address observed in a six-month-old report should still be blocked today?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of digits in the address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Freshness and current context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether it responds to ping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether it belongs to a private range<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence indicators can become stale. An IP address associated with malicious activity six months ago may have since been reassigned to a legitimate user or cloud workload. Analysts should therefore evaluate freshness, current reputation, source reliability, observed timestamps, and campaign context before using an old indicator for automatic blocking. Ping responsiveness does not establish maliciousness, and address formatting is irrelevant. Freshness is particularly important for IP intelligence because hosting providers, cloud systems, and dynamic infrastructure can change ownership quickly.<\/span><\/p>\n<p><b>Question 287.<\/b><\/p>\n<p><b>Which intelligence source would be most useful for discovering domains that historically resolved to the same suspicious IP address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Passive DNS intelligence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint registry data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS event history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passive DNS intelligence records historical mappings between domains and IP addresses. This can help analysts identify related infrastructure, discover additional domains used by the same campaign, and understand how malicious hosting changed over time. Shared hosting and cloud infrastructure can create benign relationships, so analysts should combine passive DNS with registration data, certificate information, timestamps, reputation, and campaign context. Endpoint registry and printer information cannot provide this external infrastructure history. Passive DNS is especially useful for pivoting from a single indicator to a broader set of potentially related assets.<\/span><\/p>\n<p><b>Question 288.<\/b><\/p>\n<p><b>A domain resolves to dozens of rapidly changing IP addresses with very short TTL values. Which malicious infrastructure technique could this indicate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Local ARP poisoning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP starvation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Fast-flux DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fast-flux DNS frequently changes the IP addresses associated with a domain, often using low TTL values and a distributed set of compromised or rented systems. Attackers can use this technique to make phishing, malware distribution, or command-and-control infrastructure harder to block or take down. Legitimate content-delivery networks can also use dynamic DNS behavior, so the pattern is not conclusive by itself. Analysts should examine domain age, registration data, infrastructure reputation, certificate information, autonomous systems, and endpoint behavior before classifying the activity.<\/span><\/p>\n<p><b>Question 289.<\/b><\/p>\n<p><b>Which pattern is most characteristic of command-and-control beaconing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Repeated communication from the same endpoint process to a rare destination over time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A workstation obtaining a DHCP lease<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A user browsing several approved internal sites<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A server performing its scheduled backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command-and-control beaconing commonly involves repeated outbound connections from an infected endpoint to attacker-controlled infrastructure. Analysts should examine timing, destination rarity, process identity, connection duration, byte counts, TLS metadata, and whether the pattern occurs across multiple hosts. Fixed intervals may be obvious, but sophisticated malware can add jitter or use low-frequency callbacks. Legitimate management and monitoring tools may also create regular traffic, so the initiating process and destination reputation are crucial for distinguishing benign automation from malicious beaconing.<\/span><\/p>\n<p><b>Question 290.<\/b><\/p>\n<p><b>Which security telemetry is best suited to measuring the amount of data transferred between an internal host and an external destination when payload inspection is unavailable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Badge access logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NetFlow or equivalent flow telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer usage logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS configuration records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and similar flow technologies provide metadata such as source and destination IP addresses, ports, protocols, timestamps, durations, byte counts, and packet counts. This allows analysts to identify large or unusual transfers even when application payloads are unavailable or encrypted. Flow records are especially useful for broad network visibility because they are more storage-efficient than full packet capture. Analysts should compare observed traffic with historical baselines and use endpoint, proxy, or DLP telemetry for additional context. Hardware and physical records do not provide useful data-transfer measurements.<\/span><\/p>\n<p><b>Question 291.<\/b><\/p>\n<p><b>A server suddenly sends several gigabytes of data to a cloud service that it has never contacted before. Which additional evidence would most strongly support an exfiltration hypothesis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitive files were accessed and archived shortly before the transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The server uses TCP\/IP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The transfer occurred during business hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The server has redundant power supplies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk access to sensitive data followed by archive creation and a large transfer to a previously unseen external service forms a suspicious sequence consistent with staging and exfiltration. The analyst should inspect the responsible user and process, archive contents, transfer destination, authentication events, and whether the cloud service is approved. TCP\/IP and business-hours activity are common and do not meaningfully prove or disprove exfiltration. Strong conclusions come from correlating endpoint file activity with network transfer data and business context.<\/span><\/p>\n<p><b>Question 292.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic best describes an attacker preparing gathered data for external transfer?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Initial Access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Collection includes techniques used to gather and stage information before exfiltration. Attackers may combine documents into archives, copy data into staging directories, capture screenshots, collect email, or gather database information. These actions often precede outbound transfer. Discovery focuses on learning about the environment, Initial Access concerns gaining the first foothold, and Persistence focuses on maintaining access. Analysts should examine whether collection behavior is followed by archive creation, encryption, unusual network activity, or access to external storage services.<\/span><\/p>\n<p><b>Question 293.<\/b><\/p>\n<p><b>Which source would best help determine whether a large archive was uploaded to an external SaaS platform using HTTPS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Secure web gateway or proxy telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Server fan-speed data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP scope configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Badge reader logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure web gateway and proxy logs can reveal web destinations, users, source systems, request methods, timestamps, URLs, and transferred byte counts. With application identification or TLS inspection, they may also identify cloud services, upload operations, or specific files. Even without decryption, metadata can help correlate a large outbound HTTPS session with the time an archive was created. Endpoint telemetry can identify the browser or process that initiated the upload. Hardware and physical access data do not provide application-layer network visibility.<\/span><\/p>\n<p><b>Question 294.<\/b><\/p>\n<p><b>A security analyst wants to determine whether a suspicious process established persistence through a Windows service. Which evidence would be most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical asset inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows service creation events and endpoint telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor model information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows service creation events and endpoint telemetry can reveal when a new service was installed, which executable it launches, which user created it, and what process initiated the action. Attackers frequently abuse services to establish persistence or execute code with elevated privileges. Analysts should inspect service names, executable paths, start types, digital signatures, hashes, and subsequent execution. Legitimate software installations can also create services, so the timing and context matter. Physical inventory and printer or monitor data do not provide evidence about service-based persistence.<\/span><\/p>\n<p><b>Question 295.<\/b><\/p>\n<p><b>Which forensic artifact should generally be collected before a system is powered off because it is highly volatile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> System memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printed incident forms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Archived configuration documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Asset purchase receipts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">System memory contains volatile information that can disappear immediately when power is removed. This may include running processes, active network sessions, injected code, command history, encryption keys, credentials, and other transient artifacts. If organizational procedures allow and the evidence is relevant, memory acquisition should occur before shutdown. Responders must still consider active risk; a system that is spreading malware or exfiltrating data may require rapid containment. The memory image should be documented, hashed, and protected appropriately. Paperwork and archived records are persistent and can be collected later.<\/span><\/p>\n<p><b>Question 296.<\/b><\/p>\n<p><b>Which forensic principle helps determine whether RAM, network connections, disk data, or archived records should be collected first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data normalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network segmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Order of volatility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Order of volatility prioritizes evidence based on how quickly it may change or disappear. RAM, running processes, and active connections are generally more volatile than disk data, while archived records are comparatively persistent. Investigators use this principle to plan evidence collection while balancing operational risk and containment needs. The exact order may vary based on the incident and organizational procedures. Data normalization, least privilege, and segmentation are important security concepts but do not define evidence-collection priority.<\/span><\/p>\n<p><b>Question 297.<\/b><\/p>\n<p><b>A compromised host is actively scanning internal systems and attempting remote authentication. Which incident-response action should be prioritized?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Contain or isolate the host to limit further lateral movement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Perform the final lessons-learned meeting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all authentication logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable the SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a compromised host is actively scanning and attempting to move laterally, containment should occur quickly to limit additional compromise. Depending on organizational procedures, the host may be isolated through EDR, firewall rules, switch controls, segmentation, or physical disconnection. Any critical volatile evidence should be preserved when practical, but response teams must balance forensic value with ongoing risk. Deleting logs or disabling monitoring would reduce visibility. After containment, analysts should scope affected systems and proceed with eradication.<\/span><\/p>\n<p><b>Question 298.<\/b><\/p>\n<p><b>Which task belongs primarily to the eradication phase of incident response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitoring a restored system for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Removing malicious services, resetting compromised credentials, and patching the exploited vulnerability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Developing the incident-response plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Conducting annual security awareness training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes malicious components and addresses the underlying causes of compromise. This includes deleting malware, removing malicious services and scheduled tasks, resetting stolen credentials, revoking sessions, and patching exploited vulnerabilities. Monitoring after restoration is primarily part of recovery, while planning and awareness activities belong to preparation or general security operations. Eradication must be complete because leaving behind credentials or persistence can allow the attacker to return even after the main payload is removed.<\/span><\/p>\n<p><b>Question 299.<\/b><\/p>\n<p><b>Which task belongs primarily to the recovery phase?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restore validated systems to production and monitor for renewed malicious activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create the first incident-response policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable security controls during reconnection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reuse compromised accounts without changing credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery focuses on safely returning remediated systems and services to normal operation. Before restoration, teams should verify that systems are patched, security controls are active, compromised credentials have been addressed, and known persistence mechanisms are absent. Once reconnected, systems should be monitored for signs of recurrence. Disabling controls or reusing compromised credentials would undermine the response. Recovery balances business restoration with confidence that the attacker no longer maintains access.<\/span><\/p>\n<p><b>Question 300.<\/b><\/p>\n<p><b>A post-incident review finds that analysts could not quickly connect suspicious user activity to the associated endpoint and network events. Which improvement would provide the greatest benefit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce identity logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete old endpoint telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Improve correlation using common user, host, IP, and timestamp fields across security data sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable behavioral analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlation depends on consistent identifiers that allow analysts to connect identity, endpoint, and network activity into one timeline. Common fields such as username, hostname, IP address, process ID, device identifier, and timestamp enable SIEM rules and investigators to pivot between data sources efficiently. Normalization and accurate time synchronization further improve this process. Reducing logging or deleting historical telemetry would make investigations harder. Post-incident improvement should focus on integrating and correlating existing data so analysts can recognize attack chains more quickly and respond with greater confidence.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 281. A SOC analyst sees a privileged account authenticate to several servers from a workstation that is normally used only for email and web browsing. Which interpretation is most appropriate? The activity may indicate credential misuse or lateral movement and should [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23794"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23794"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23794\/revisions"}],"predecessor-version":[{"id":23795,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23794\/revisions\/23795"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}