{"id":23800,"date":"2026-09-28T10:00:26","date_gmt":"2026-09-28T10:00:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23800"},"modified":"2026-09-28T10:00:26","modified_gmt":"2026-09-28T10:00:26","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 341.<\/b><\/p>\n<p><b>A SOC analyst notices that an account belonging to a departed employee successfully authenticated to an internal application. What should the analyst investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the account should have been disabled and whether its credentials were misused<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether the application server has enough storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether DHCP renewed the server lease<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the user&#8217;s old workstation is still under warranty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An account associated with a departed employee should normally be disabled or otherwise removed from active use according to the organization&#8217;s offboarding process. A successful authentication therefore raises the possibility of an access-control failure or credential misuse. The analyst should review the account status, source IP, device, MFA activity, authentication method, resources accessed, and any actions performed after login. The event should also prompt a review of offboarding controls to determine whether other former-employee accounts remain active. Storage, DHCP, and warranty information do not explain the unauthorized authentication. If compromise is confirmed, active sessions should be revoked and the incident scoped for additional activity.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>Which security control would most directly reduce the risk of former employees retaining access to enterprise systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disk encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A formal identity deprovisioning and offboarding process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network time synchronization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A formal identity deprovisioning process ensures that accounts, tokens, application access, remote-access privileges, and other credentials are disabled or removed when a user leaves the organization. Offboarding should also include device return, ownership reassignment, shared-secret changes where appropriate, and validation that access has actually been revoked. Disk encryption protects stored data but does not terminate identity access. Time synchronization and printer auditing serve other purposes. Weak offboarding creates a long-lived attack surface because forgotten accounts can be abused without immediately attracting attention. Organizations should automate deprovisioning where possible and periodically audit inactive accounts.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>A security analyst sees a user account continue to access cloud applications after its primary password has been reset. Which explanation should be considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP spoofing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An existing session token or refresh token may still be valid<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modern cloud authentication often uses session tokens or refresh tokens after the initial login. Resetting a password may not always terminate every active session immediately, depending on the identity platform and application. If an attacker possesses a valid token, access may continue even after the password changes. Analysts should review identity-provider logs, active sessions, token issuance, device information, and application access. Containment may require revoking sessions and refresh tokens in addition to changing credentials. DNS, DHCP, and ARP attacks do not explain continued cloud access after a password reset. This scenario demonstrates why credential remediation must consider tokens and sessions, not only passwords.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>Which response action is most appropriate when an identity compromise includes stolen session tokens?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only change the user&#8217;s display name<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Wait for the tokens to expire naturally<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable endpoint logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Revoke active sessions and tokens in addition to resetting credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If session or refresh tokens may have been stolen, password reset alone may not terminate attacker access. The response team should revoke active sessions and tokens using the capabilities of the relevant identity platform, then reset affected credentials and investigate how the tokens were obtained. The account&#8217;s recent authentication history and application activity should also be reviewed for unauthorized access. Waiting for expiration can leave the attacker active for an unacceptable period. Changing a display name has no security value, while disabling logging would remove important visibility. Identity containment should address every authentication mechanism that may have been compromised.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>A SIEM alert shows a privileged user granting an unfamiliar account membership in a highly privileged group. What should the analyst investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The legitimacy of the group membership change and the account that initiated it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The destination server&#8217;s monitor resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The DHCP lease duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The user&#8217;s printer settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unexpected membership changes involving highly privileged groups can indicate privilege escalation, persistence, or administrative account misuse. The analyst should determine which account initiated the change, from which system, whether the action was authorized, and what the newly privileged account did afterward. Identity logs, directory-service events, endpoint telemetry, change tickets, and administrator activity should be correlated. If the account was added without authorization, the change may need to be reversed quickly according to incident-response procedures. Monitor, DHCP, and printer information do not address the security significance of the privilege modification.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic best describes an attacker adding a compromised account to an administrative group to gain higher privileges?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Privilege Escalation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reconnaissance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Adding an account to a privileged group is directly associated with Privilege Escalation because the attacker is increasing the permissions available to that identity. Depending on the environment, the same action can also support persistence if the attacker intends to retain administrative access over time. Collection focuses on gathering data, Reconnaissance on learning about targets, and Exfiltration on transferring data out. Analysts should review who made the group change, whether the account was previously compromised, and what privileged actions followed. Privilege modifications should be monitored closely because they can dramatically increase attacker capability.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>A security team wants to detect unauthorized changes to privileged group membership more quickly. Which approach is most effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable directory auditing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Monitor only password failures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Alert on privileged group modifications and enrich the alert with user, host, and change context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore changes made by administrator accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged group membership changes are high-value security events. Monitoring them and automatically enriching alerts with the initiating user, target account, source host, timestamp, ticket or approval context, and subsequent activity gives analysts the information needed for fast triage. Ignoring administrator activity would be dangerous because compromised administrative credentials are often used for privilege escalation. Password failures alone do not capture privilege changes, and disabling auditing would remove critical visibility. The best detection approach combines directory events with endpoint and identity context so authorized administration can be distinguished from suspicious modification.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>A SOC analyst sees a privileged account create a new local administrator account on multiple servers. Which attacker objective does this most likely support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Network availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating new local administrator accounts can provide persistent access even if the original compromised account is later disabled. Attackers may create redundant privileged accounts on multiple systems to preserve control and make eradication more difficult. Analysts should determine which account performed the creation, which hosts were affected, whether the accounts were used, and whether similar changes occurred elsewhere. Legitimate automation can also create accounts, so change-management context matters. If malicious, the accounts should be contained and removed according to response procedures, and the original credential compromise should be investigated.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>Which telemetry would best help determine whether a newly created administrator account was later used for remote access?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication logs correlated with endpoint and remote-access events<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer spooler data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor serial numbers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication and remote-access logs can show whether the newly created account successfully logged in, from which source host, to which destination, and using what authentication mechanism. Endpoint telemetry can then reveal the commands and processes executed after authentication. This correlation is important because account creation alone indicates possible persistence, while subsequent use demonstrates that the account actually became part of attacker activity. Printer, BIOS, and monitor information provide no useful identity context. Analysts should also determine whether the account was used across multiple systems and whether it created further persistence or accessed sensitive resources.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>A compromised account accesses a cloud application from a new device and immediately downloads thousands of files. Which factor most increases the alert priority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user&#8217;s account name is long<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The files contain sensitive business data and the behavior deviates sharply from the user&#8217;s baseline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The application uses HTTPS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The device receives a private IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Alert priority should consider both likelihood and potential impact. A new device, abnormal bulk downloading, and access to sensitive data create a high-risk combination, especially if the user has no history of performing such activity. Analysts should review authentication factors, source location, device identity, session history, file types, download volume, and whether the account showed other signs of compromise. HTTPS and private IP addressing are normal and do not meaningfully reduce risk. Behavioral baselines and data sensitivity are valuable contextual signals for prioritizing identity-related incidents.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>Which security capability is most useful for identifying anomalous cloud-user behavior such as unusual download volume or access from unfamiliar devices?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User and entity behavior analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File-system defragmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> VLAN pruning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and entity behavior analytics can identify deviations in login locations, device usage, download volume, application access, and other patterns associated with users and systems. This is particularly useful in cloud environments where attackers may use valid credentials and never deploy malware. UEBA can highlight behavior that differs significantly from the user&#8217;s historical baseline, but anomalies still require investigation because legitimate changes can occur. The strongest analysis combines UEBA with identity-provider logs, cloud application telemetry, endpoint data, and asset context. Network and hardware maintenance functions do not provide comparable behavioral insight.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>Which evidence would best help determine whether a large cloud download was followed by local data staging?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Badge-reader logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint file and process telemetry showing archive creation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer supply information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP scope utilization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint file and process telemetry can reveal whether downloaded files were grouped, compressed, encrypted, or moved into a staging directory after arriving on the device. Archive creation shortly after a large cloud download may indicate preparation for further exfiltration or transfer. Analysts should identify the process responsible, archive size, contents, user account, and any subsequent outbound network activity. Physical and DHCP telemetry do not provide this file-level context. Correlating cloud activity with endpoint behavior helps determine whether the download represents legitimate work or part of a broader data-theft sequence.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>A workstation creates a large archive containing confidential files and then begins an outbound connection to a rare destination. Which next step provides the strongest confirmation of exfiltration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Correlate archive size and creation time with outbound transfer volume and destination telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Check whether the workstation has an SSD<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Verify the screen-lock policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Review the keyboard layout<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The strongest evidence comes from correlating endpoint and network events. If a large archive containing confidential files is created and shortly afterward a transfer of similar size occurs to a rare external destination, the sequence strongly supports an exfiltration hypothesis. Analysts should identify the uploading process, protocol, destination reputation, account context, and whether the transfer completed successfully. Storage type and workstation configuration do not establish exfiltration. Correlation of file staging and network transfer provides a more defensible conclusion than either event alone.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>Which telemetry source is best for measuring outbound byte volume when complete packet payloads are not retained?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BIOS event logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NetFlow or equivalent flow telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical security logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetFlow and similar flow technologies record metadata such as source and destination IP addresses, ports, protocols, session duration, packet counts, and byte counts. This makes them useful for measuring outbound traffic volume and identifying anomalous transfers without storing complete packet contents. Flow records can help analysts spot data exfiltration, command-and-control patterns, or scanning across large environments. They do not reveal exact file contents, so endpoint, DLP, proxy, or packet data may be needed for deeper analysis. Hardware and physical-access sources do not provide network transfer metrics.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>A forensic investigator is examining a live compromised host. Which evidence should generally be collected before shutdown when active sessions and encryption keys may be important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Volatile memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Asset purchase records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Archived invoices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printed rack diagrams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Volatile memory may contain active sessions, network connections, process information, credentials, encryption keys, injected code, and other artifacts that can disappear when the system is powered off. If these artifacts are relevant and organizational procedures permit collection, memory should be acquired before shutdown. Responders still need to balance evidence collection with containment risk, particularly if the system is actively causing harm. The collected memory image should be documented, hashed, and securely stored. Business records and printed diagrams are persistent and do not require the same immediate priority.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>Which forensic principle determines that volatile memory should usually be collected before persistent disk data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Segmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data normalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Order of volatility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Order of volatility prioritizes evidence based on how quickly it can change or disappear. RAM, active network connections, running processes, and similar live-system information are generally more volatile than files stored on disk. Investigators use this concept to plan collection while considering the operational need to contain an active threat. The exact collection sequence can vary with the incident, but volatile artifacts typically receive earlier attention. Least privilege, segmentation, and normalization are important security concepts but do not determine forensic evidence collection priority.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>A compromised host is actively using stolen credentials to access additional servers. Which response action should be prioritized once critical volatile evidence is collected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Isolate the source host and restrict the compromised credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Wait until the next monthly maintenance window<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete identity logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an attacker is actively moving laterally, containment should address both the compromised endpoint and the abused identity. Isolating the host can stop further network activity, while disabling or restricting the account and revoking active sessions can prevent the attacker from continuing to authenticate elsewhere. The exact action should follow organizational incident-response procedures and account for business impact. Waiting unnecessarily increases risk. Deleting logs or disabling monitoring would hinder investigation. After containment, the team should scope affected systems and proceed with eradication.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>Which activity belongs primarily to the eradication phase after a compromised identity has been contained?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conducting the final post-incident review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Resetting compromised credentials, removing malicious persistence, and patching exploited weaknesses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reconnecting all systems immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication addresses the attacker&#8217;s remaining access and the underlying causes of compromise. This can include credential resets, token revocation, removal of malicious services or scheduled tasks, deletion of unauthorized accounts, patching vulnerabilities, and rebuilding systems when necessary. Containment limits immediate activity but does not remove every foothold. Recovery should not begin until the team has reasonable confidence that attacker access has been eliminated. The final review occurs after recovery, while disabling controls would make the environment less secure.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>Which task belongs primarily to recovery after identity and endpoint compromise have been eradicated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restore validated systems and accounts to service while monitoring closely for recurrence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reuse the original compromised passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable identity auditing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete all incident evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery restores business operations in a controlled manner after the threat has been removed. Systems should be validated, patched, protected, and reconnected carefully. Accounts should have new credentials or tokens where appropriate, and security controls should remain active. Enhanced monitoring should continue for signs of renewed authentication anomalies, beaconing, or persistence. Reusing compromised passwords or disabling identity auditing would undermine the response. Evidence and incident documentation should be retained according to organizational requirements for review, compliance, and lessons learned.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>A post-incident review reveals that an old employee account remained active for months and was later abused by an attacker. Which improvement would most directly prevent recurrence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce log retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable behavioral analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automate joiner-mover-leaver identity lifecycle controls and regularly audit inactive accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow former employees to retain limited access indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strong identity lifecycle management ensures that accounts are provisioned, modified, and deprovisioned promptly as employment status and job roles change. Automating joiner-mover-leaver workflows reduces dependence on manual action and helps prevent orphaned accounts. Regular audits can detect inactive, stale, excessive, or incorrectly privileged identities that automation may have missed. Leaving former-employee accounts active creates unnecessary attack surface, while reducing monitoring would make abuse harder to detect. Post-incident lessons should address both the immediate compromise and the process weakness that allowed the unused account to remain exploitable.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 341. A SOC analyst notices that an account belonging to a departed employee successfully authenticated to an internal application. What should the analyst investigate first? Whether the account should have been disabled and whether its credentials were misused 2. Whether the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23800"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23800"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23800\/revisions"}],"predecessor-version":[{"id":23801,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23800\/revisions\/23801"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}