{"id":23798,"date":"2026-09-28T10:00:11","date_gmt":"2026-09-28T10:00:11","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23798"},"modified":"2026-09-28T10:00:11","modified_gmt":"2026-09-28T10:00:11","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 321.<\/b><\/p>\n<p><b>A SOC analyst observes a domain administrator account authenticating to several endpoints from a workstation that is normally assigned to a standard business user. Which action should the analyst take first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigate the source workstation and account activity for possible credential compromise<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume the activity is legitimate because the account is privileged<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace the destination endpoints<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable DNS on the source workstation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A domain administrator account being used from an unexpected workstation is a high-risk anomaly because privileged credentials can provide broad access across an environment. The analyst should determine whether the account owner intentionally used the workstation, review MFA and authentication events, and examine endpoint telemetry from the source host for credential theft, remote administration, or suspicious process execution. The analyst should also review what occurred on destination systems after authentication. Privileged status does not make unusual activity automatically legitimate. If compromise is confirmed, containment may require restricting the account, revoking active sessions, rotating credentials, and isolating the source host while the wider scope is investigated.<\/span><\/p>\n<p><b>Question 322.<\/b><\/p>\n<p><b>Which data source would best help determine whether the source workstation in the previous scenario executed a credential-dumping tool before the privileged logins occurred?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer server logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint detection and response telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP scope utilization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Badge-reader events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response telemetry provides process-level visibility that can reveal suspicious executable launches, memory-access behavior, command-line activity, file creation, and parent-child process relationships. This makes it highly useful when investigating whether credentials were stolen before privileged authentication occurred. Authentication logs show how the account was used but generally do not reveal the process responsible for obtaining credentials. DHCP data can help identify host addressing at a particular time, while printer and physical access records do not provide relevant process telemetry. Analysts should correlate endpoint events with authentication timestamps to establish whether credential access preceded the suspicious logins.<\/span><\/p>\n<p><b>Question 323.<\/b><\/p>\n<p><b>An analyst detects a process attempting to access authentication material from LSASS memory. Which attacker objective is most likely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data exfiltration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Credential Access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Resource Development<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accessing LSASS memory is commonly associated with attempts to obtain passwords, password hashes, tokens, or other authentication material. In MITRE ATT&amp;CK terminology, this aligns with Credential Access. Attackers may use stolen credentials to escalate privileges, move laterally, access sensitive resources, or establish additional persistence. Not every process interacting with LSASS is malicious because legitimate security software can also inspect sensitive processes, so analysts should examine the executable, signature, process ancestry, user context, and surrounding activity. When suspicious LSASS access is observed alongside unusual authentication, it should generally receive high investigative priority.<\/span><\/p>\n<p><b>Question 324.<\/b><\/p>\n<p><b>Which detection strategy is most effective for identifying credential dumping when an attacker uses a legitimate or renamed utility?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search only for one known filename<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block every administrative tool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore signed executables<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Detect suspicious access to credential-related processes and associated behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers can rename tools, modify binaries, or abuse legitimate utilities, making filename-only detection fragile. Behavioral detection that focuses on suspicious interaction with credential-related processes, memory access patterns, process relationships, privilege changes, and subsequent authentication activity is more resilient. Blocking all administrative software would disrupt legitimate operations, while ignoring signed binaries creates dangerous blind spots. Analysts should combine endpoint behavior with identity telemetry and threat intelligence. If suspicious credential access is confirmed, the response should include investigation of accounts that may have been exposed and review of subsequent logins across the environment.<\/span><\/p>\n<p><b>Question 325.<\/b><\/p>\n<p><b>A workstation begins authenticating to many servers shortly after a suspicious process accessed credential material. What is the most likely interpretation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stolen credentials may be being used for lateral movement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A routine DHCP renewal is occurring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The host is performing normal NTP synchronization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The user is changing local display settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential-access activity followed by authentication to multiple systems is a suspicious sequence consistent with credential theft and lateral movement. The analyst should review the accounts used, destination systems, authentication protocols, successful and failed logins, and any remote process execution that followed. Endpoint telemetry from the source host can reveal which process initiated the connections, while destination telemetry can show what the attacker did after login. DHCP and NTP activity do not explain the authentication pattern. If lateral movement is confirmed, analysts should assume the incident may extend beyond the original workstation and scope additional systems and identities accordingly.<\/span><\/p>\n<p><b>Question 326.<\/b><\/p>\n<p><b>Which identity-related pattern is most useful for detecting an account being used from a new endpoint and accessing an unusual set of systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware inventory matching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User and entity behavior analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> File carving<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Packet fragmentation analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and entity behavior analytics can identify deviations from normal account and device behavior, such as authentication from new endpoints, abnormal resource access, unusual login times, or rapid access to many systems. These anomalies are especially useful when attackers use valid credentials and do not deploy obvious malware. UEBA depends on sufficient historical data and accurate identity context, and anomalies must still be investigated because legitimate business changes can also produce deviations. File carving and packet fragmentation analysis serve different purposes. Behavioral identity analytics are most valuable when combined with endpoint and network telemetry.<\/span><\/p>\n<p><b>Question 327.<\/b><\/p>\n<p><b>An analyst sees a user account authenticate successfully from Pakistan and then five minutes later from a distant country with no corporate VPN involved. Which alert type is most applicable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Impossible-travel anomaly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP spoofing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Port scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Impossible-travel analytics identify authentication events that occur from geographically distant locations within a timeframe that makes legitimate physical travel implausible. This can indicate stolen credentials or token compromise. The analyst should still validate the event because proxies, cloud services, mobile networks, and VPNs can affect geolocation. Device identity, MFA events, source IP reputation, user-agent data, session activity, and the user&#8217;s normal access pattern should all be reviewed. DNS tunneling, ARP spoofing, and port scanning describe different technical behaviors unrelated to geographically inconsistent authentication.<\/span><\/p>\n<p><b>Question 328.<\/b><\/p>\n<p><b>Which factor should an analyst evaluate before treating an impossible-travel alert as confirmed compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the account has a long username<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether one of the sessions used a corporate VPN or proxy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the user owns a laptop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the destination application uses HTTPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPNs, proxies, cloud gateways, and mobile carriers can make legitimate authentication appear to originate from different geographic locations. Analysts should therefore determine whether a corporate VPN or other routing service explains the apparent travel anomaly. They should also review device identifiers, authentication factors, user behavior, and source IP reputation. A long username, laptop ownership, or HTTPS use does not explain the geography. Impossible-travel detections are useful prioritization signals, but they should be validated with additional identity and network context before high-impact containment actions are taken.<\/span><\/p>\n<p><b>Question 329.<\/b><\/p>\n<p><b>A SOC observes an endpoint repeatedly connecting to a rare domain over HTTPS, but the connection intervals vary by several minutes. Which additional telemetry would best help determine whether this is malicious beaconing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The process responsible for the connections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The user&#8217;s desktop theme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer toner levels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware warranty status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process attribution is one of the most useful ways to determine whether periodic network activity is malicious. If the communication originates from a trusted management agent connecting to its normal vendor infrastructure, the pattern may be legitimate. If it comes from an unsigned executable in a temporary directory or a suspicious script process, the same network behavior becomes much more concerning. Analysts should also examine domain age, destination reputation, TLS certificate information, data volumes, and timing characteristics. Variable intervals may indicate jitter, but jitter alone is not proof of malware.<\/span><\/p>\n<p><b>Question 330.<\/b><\/p>\n<p><b>What is the primary purpose of jitter in command-and-control communication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To improve endpoint storage performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To make periodic beaconing less predictable and harder to detect<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To increase DNS TTL values<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To accelerate DHCP lease renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jitter introduces random variation into the timing of command-and-control callbacks. Instead of connecting at an exact fixed interval, malware may vary delays so periodic behavior is less obvious to simple threshold or timing-based detections. Security analysts can still identify jittered beaconing by examining longer-term patterns, destination rarity, process identity, byte counts, and relationships between multiple hosts. Jitter does not make communication invisible; it simply reduces regularity. Storage performance, DNS TTL values, and DHCP renewal have no direct relationship to this command-and-control technique.<\/span><\/p>\n<p><b>Question 331.<\/b><\/p>\n<p><b>A compromised endpoint creates an encrypted archive containing files copied from multiple internal servers. Which MITRE ATT&amp;CK tactic most directly describes the gathering of those files?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Defense Evasion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Initial Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gathering files from multiple systems aligns with the Collection tactic because the adversary is acquiring information of interest before using or exfiltrating it. Creating an encrypted archive may also represent data staging in preparation for transfer. Analysts should identify the account used to access the files, the process responsible for collection, the archive location, and any outbound network activity that followed. Persistence maintains access, Defense Evasion avoids detection, and Initial Access concerns the original foothold. Mapping the behavior to ATT&amp;CK helps structure the investigation and identify additional techniques that may occur next.<\/span><\/p>\n<p><b>Question 332.<\/b><\/p>\n<p><b>Which telemetry would best identify whether the encrypted archive from the previous scenario was transferred outside the organization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitor inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Proxy, firewall, NetFlow, or cloud-access telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer spooler logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network and cloud-access telemetry can show whether a large outbound transfer occurred after the archive was created. Proxy and secure web gateway logs may identify URLs, cloud applications, usernames, and byte counts. Firewall and flow telemetry can provide source, destination, protocol, session duration, and data volume. Analysts should correlate transfer size and timing with archive creation and endpoint process telemetry. Hardware and printer information do not provide outbound transfer evidence. Correlation is essential because archive creation alone proves staging, not successful exfiltration.<\/span><\/p>\n<p><b>Question 333.<\/b><\/p>\n<p><b>A host uploads several gigabytes to a cloud service that is approved for business use. Which factor would most increase suspicion that the transfer is malicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The upload is performed by an unusual process shortly after bulk access to sensitive files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The cloud service supports HTTPS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The endpoint uses Ethernet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The user has a corporate account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers may abuse legitimate cloud services for exfiltration, so the fact that a destination is approved does not automatically make every transfer safe. Bulk access to sensitive files followed by an upload from an unusual process is highly relevant context. The analyst should review the account, process, file access, transfer size, destination tenant or account, and whether the user has a legitimate business reason for the activity. HTTPS, Ethernet, and corporate authentication are common and provide little evidence either way. Context and sequence matter more than simple destination reputation.<\/span><\/p>\n<p><b>Question 334.<\/b><\/p>\n<p><b>Which control would most help detect unauthorized upload of sensitive data to sanctioned cloud applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer auditing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CASB or cloud-access security monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS password configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP reservations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Access Security Broker or comparable cloud-access security monitoring capability can provide visibility into sanctioned and unsanctioned cloud applications, users, file transfers, access patterns, and policy violations. This can help detect sensitive data being uploaded to legitimate cloud platforms in ways that violate organizational policy. Secure web gateways, DLP systems, and endpoint telemetry may provide complementary evidence. BIOS and DHCP controls do not monitor cloud application usage. Because legitimate cloud services can be abused by insiders or compromised accounts, cloud-aware monitoring is an important component of modern incident detection.<\/span><\/p>\n<p><b>Question 335.<\/b><\/p>\n<p><b>Which forensic evidence should generally be collected before powering off a live compromised host if the investigation requires active network-connection information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Volatile memory and current connection data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Archived invoices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printed floor plans<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware purchase receipts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Active network connections and memory-resident information are volatile and may disappear when a system is shut down. Depending on the incident and organizational procedures, investigators may capture RAM, connection tables, running processes, logged-in users, and related live-response information before powering down the system. The need to preserve volatile evidence must be balanced against containment risk because a live host may continue communicating with an attacker. Persistent business documents can be collected later. Investigators should document all actions because live-response collection itself changes the system state.<\/span><\/p>\n<p><b>Question 336.<\/b><\/p>\n<p><b>Which forensic practice is most important for showing that a disk image remained unchanged after acquisition?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change its filename periodically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Compress it several times<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store it in multiple folders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Calculate and later verify a cryptographic hash<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash provides a reproducible integrity value based on the contents of the forensic image. If a later hash matches the value recorded at acquisition, investigators gain confidence that the evidence has not been modified. Renaming, compressing, or relocating the file does not provide equivalent integrity assurance and can sometimes alter its representation. Hashing should be combined with chain-of-custody records, secure storage, restricted access, and analysis on verified working copies. Evidence integrity is especially important when findings may be reviewed by legal, regulatory, or disciplinary authorities.<\/span><\/p>\n<p><b>Question 337.<\/b><\/p>\n<p><b>A compromised workstation is actively attempting to authenticate to many internal systems. Which incident-response action should be prioritized after any immediately required volatile evidence is collected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Isolate the workstation from the network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Conduct the lessons-learned meeting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all authentication logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Active authentication attempts from a compromised host create an immediate risk of lateral movement. Network isolation can stop further connection attempts, command-and-control communication, and malware propagation while preserving the system for deeper investigation. Depending on organizational procedures, isolation may be performed through EDR controls, firewall rules, segmentation, switch configuration, or physical disconnection. Lessons learned occurs later, while deleting logs or disabling monitoring would reduce visibility. After containment, analysts should determine which accounts were used and whether any additional systems were already compromised.<\/span><\/p>\n<p><b>Question 338.<\/b><\/p>\n<p><b>Which action belongs primarily to eradication rather than containment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Blocking a malicious IP temporarily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Removing persistence, resetting compromised credentials, and patching the exploited vulnerability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Isolating an endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Restricting an account during investigation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes the attacker&#8217;s footholds and addresses the conditions that enabled compromise. Removing persistence, resetting stolen credentials, revoking active sessions, and patching vulnerabilities are all eradication activities. Temporary network blocks, endpoint isolation, and account restrictions are generally containment measures because they limit immediate risk while the investigation continues. Recovery should not begin until the response team has sufficient confidence that malicious access has been removed. In severely compromised environments, rebuilding from trusted images may provide greater assurance than manual cleaning.<\/span><\/p>\n<p><b>Question 339.<\/b><\/p>\n<p><b>Which action is most appropriate during recovery after systems have been rebuilt and malicious persistence removed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restore systems in a controlled manner and monitor closely for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable security telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reuse compromised passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete all incident evidence immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery returns systems to normal operation after containment and eradication have addressed the threat. Before reconnecting systems, responders should validate patching, security controls, credentials, configuration, and application functionality. Once production access is restored, enhanced monitoring should continue for a period to detect renewed command-and-control communication, suspicious authentication, or persistence behavior. Security telemetry should remain enabled, and compromised credentials should not be reused. Incident evidence should be retained according to organizational requirements so lessons can be learned and any formal review can be supported.<\/span><\/p>\n<p><b>Question 340.<\/b><\/p>\n<p><b>A post-incident review finds that a compromised service account had excessive privileges on many servers, significantly increasing the attacker&#8217;s reach. Which improvement should be prioritized?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce log retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable identity monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply least privilege and review service-account permissions and usage regularly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow service accounts to log in interactively everywhere<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service accounts should receive only the permissions required for their intended applications and should generally be restricted from unnecessary interactive use. Excessive privileges increase the impact of credential compromise because attackers can use one account to access many systems. The organization should review service-account privileges, restrict login locations and methods, rotate credentials appropriately, monitor usage, and consider managed service-account technologies where suitable. Reducing logging or expanding access would worsen the risk. Post-incident reviews should address structural weaknesses such as excessive privileges so the same type of compromise has a smaller impact in the future.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 321. A SOC analyst observes a domain administrator account authenticating to several endpoints from a workstation that is normally assigned to a standard business user. Which action should the analyst take first? Investigate the source workstation and account activity for possible [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23798"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23798"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23798\/revisions"}],"predecessor-version":[{"id":23799,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23798\/revisions\/23799"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}