{"id":23804,"date":"2026-09-28T10:01:02","date_gmt":"2026-09-28T10:01:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23804"},"modified":"2026-09-28T10:01:02","modified_gmt":"2026-09-28T10:01:02","slug":"cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-cybersecurity-300-215-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco CCNP CyberSecurity 300-215 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-215-exam-dumps\"><b>Cisco CCNP CyberSecurity 300-215 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 381.<\/b><\/p>\n<p><b>A SOC analyst observes an account successfully authenticating to a critical server from a host that was recently isolated for malware activity. What should the analyst do first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigate whether the credentials were compromised and whether the session is still active<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume the login is legitimate because authentication succeeded<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the endpoint telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reboot the critical server immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A successful login from a host already associated with malware is highly suspicious because the attacker may have stolen credentials before the system was isolated. The analyst should review authentication events, session information, privilege level, destination activity, MFA results, and whether additional systems were accessed. Endpoint telemetry from the compromised source host may reveal credential theft, remote-access tools, or commands that preceded the authentication. Rebooting the server without understanding the event could destroy volatile evidence, while deleting telemetry would remove valuable context. If compromise is confirmed, the account may need to be restricted, sessions revoked, credentials rotated, and related authentication activity hunted across the environment.<\/span><\/p>\n<p><b>Question 382.<\/b><\/p>\n<p><b>Which source would best help determine whether the suspicious login in the previous scenario was followed by remote command execution?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Endpoint process telemetry on the destination server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP scope utilization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Badge-reader events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process telemetry on the destination server can show which executables launched after the authentication, along with command lines, parent-child relationships, user context, file paths, and network activity. This allows the analyst to determine whether the session involved legitimate access or remote command execution. Authentication logs identify that access occurred but may not reveal what happened afterward. DHCP and physical-access records do not provide process-level evidence. Analysts should align timestamps from authentication and endpoint data to reconstruct the sequence accurately and identify any lateral movement, privilege escalation, or persistence established after login.<\/span><\/p>\n<p><b>Question 383.<\/b><\/p>\n<p><b>An analyst sees <\/b><b>psexec<\/b><b>-like remote service execution from a compromised workstation to multiple servers. Which attacker behavior is most likely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reconnaissance only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Lateral Movement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote service execution from a compromised workstation to multiple servers is strongly associated with Lateral Movement. Attackers often use valid credentials and remote execution mechanisms to expand access after compromising one endpoint. The analyst should examine the source account, destination systems, service creation events, process telemetry, transferred binaries, and whether the same technique appears elsewhere. Collection involves gathering data, Reconnaissance focuses on target information gathering, and Exfiltration concerns transferring data externally. Lateral movement should generally trigger broader incident scoping because compromise may no longer be limited to the original workstation.<\/span><\/p>\n<p><b>Question 384.<\/b><\/p>\n<p><b>Which detection approach is most effective for identifying suspicious remote service execution without alerting on every legitimate administrative action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block every remote service operation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Alert only on one known executable name<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore activity performed by administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Correlate remote service creation with unusual users, source hosts, binaries, and process behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remote service creation can be legitimate in enterprise administration, so context is essential. A stronger detection looks for unexpected source hosts, unusual accounts, unknown executables, suspicious service names, uncommon paths, or service creation immediately after anomalous authentication. Blocking all remote service operations would disrupt normal management, while relying on one filename is too narrow because attackers can rename tools. Ignoring administrator activity is also dangerous because privileged credentials are often compromised. Behavioral correlation provides broader coverage while reducing false positives.<\/span><\/p>\n<p><b>Question 385.<\/b><\/p>\n<p><b>A workstation launches a script interpreter that downloads a file and then contacts a rare external domain. Which investigative method best helps establish whether these events are related?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Build a correlated process and network timeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the file extension<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace the network cable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the script after execution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A correlated timeline can show whether the script interpreter downloaded the file, whether that file executed, and whether the resulting process contacted the rare domain. Endpoint telemetry, DNS, proxy, firewall, and file events should be aligned using accurate timestamps. Looking only at a file extension provides very limited evidence. Replacing hardware does not address the suspected attack chain, and deleting the script immediately may remove useful evidence. Timeline analysis is one of the most effective ways to understand causality and sequence across multiple telemetry sources.<\/span><\/p>\n<p><b>Question 386.<\/b><\/p>\n<p><b>Which threat-intelligence attribute should be reviewed before treating a domain indicator from an old report as currently malicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Domain length<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Freshness and current reputation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of vowels in the domain name<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the domain supports IPv6<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence indicators can become stale because domains and infrastructure change ownership or usage over time. An indicator that was malicious months ago may no longer represent an active threat. Analysts should evaluate freshness, current reputation, source confidence, registration details, passive DNS history, and recent observations before taking action. Domain length and IPv6 support are not meaningful measures of maliciousness. Old indicators can still be useful for retrospective searches, but automatic blocking should generally depend on current context and confidence.<\/span><\/p>\n<p><b>Question 387.<\/b><\/p>\n<p><b>Which intelligence source is most useful for identifying historical IP addresses associated with a suspicious domain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Passive DNS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BIOS configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Local group policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passive DNS records historical domain-to-IP relationships, making it useful for understanding how suspicious infrastructure has changed over time. Analysts can identify previous hosting addresses, related domains, and possible campaign infrastructure. This can support threat hunting and incident scoping. Because cloud and shared hosting environments can create benign associations, passive DNS should be combined with timestamps, certificate information, registration records, and reputation data. Printer, BIOS, and local policy data do not provide external DNS history.<\/span><\/p>\n<p><b>Question 388.<\/b><\/p>\n<p><b>An endpoint repeatedly sends small HTTPS connections to the same destination every few minutes, but with variable timing. Which technique may the malware be using?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP renewal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ARP inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Jittered beaconing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> VLAN hopping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jittered beaconing introduces random variation into command-and-control callback intervals. Instead of communicating at perfectly fixed times, malware may vary the delay to make the traffic less obvious to periodicity-based detections. Analysts should still examine destination rarity, process identity, TLS metadata, byte counts, and long-term patterns. Legitimate management agents can also use variable polling intervals, so the responsible process and business context are essential. DHCP, ARP inspection, and VLAN hopping are unrelated to this recurring outbound behavior.<\/span><\/p>\n<p><b>Question 389.<\/b><\/p>\n<p><b>Which source would best determine which process is responsible for suspected jittered beaconing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint process-to-network telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Badge-reader logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Printer spooler records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hardware inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint process-to-network telemetry can associate each connection with a specific executable, user, parent process, command line, and file path. This is critical for distinguishing malware from legitimate automated software. If the process is an unsigned binary in a temporary directory, suspicion increases; if it is a known management agent communicating with approved infrastructure, the traffic may be benign. Network telemetry alone can show timing and destination but may not reveal the responsible process. Combining endpoint and network evidence provides the strongest analysis.<\/span><\/p>\n<p><b>Question 390.<\/b><\/p>\n<p><b>A security analyst sees repeated DNS requests containing long encoded-looking subdomains. Which behavior is most likely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Normal DHCP activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS tunneling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Standard NTP synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling often encodes data into DNS queries or responses, producing unusually long or high-entropy subdomains. This can be used for command-and-control or data exfiltration because DNS is commonly permitted through network controls. Analysts should inspect query length, frequency, entropy, domain reputation, record types, and the endpoint process generating the traffic. Legitimate services can also create complex DNS names, so the behavior should be validated with context. DHCP, ARP, and NTP have different communication patterns and would not normally generate this type of encoded DNS activity.<\/span><\/p>\n<p><b>Question 391.<\/b><\/p>\n<p><b>Which combination of evidence most strongly supports a DNS tunneling hypothesis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> High-entropy queries, high query volume, a rare domain, and a suspicious initiating process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> One ordinary lookup to a popular domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A normal reverse lookup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A workstation using an internal DNS server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multiple reinforcing indicators provide much stronger evidence than any single DNS anomaly. High-entropy subdomains, repeated queries to a rare domain, abnormal query volume, and a suspicious endpoint process together create a strong tunneling hypothesis. Analysts should still examine whether the application has a legitimate business function that could explain the traffic. Looking at only one ordinary lookup provides little evidence. DNS investigations are most effective when server-side query data is correlated with endpoint process telemetry and threat intelligence.<\/span><\/p>\n<p><b>Question 392.<\/b><\/p>\n<p><b>Which MITRE ATT&amp;CK tactic best describes an attacker enumerating domain users, groups, and network shares after initial compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exfiltration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Discovery covers techniques used to learn about the victim environment after access has been obtained. Enumerating domain users, groups, systems, shares, and services helps attackers identify valuable targets and paths for privilege escalation or lateral movement. Impact concerns disruption, Exfiltration concerns data removal, and Persistence concerns maintaining access. Analysts should determine which process performed the enumeration and what actions followed. Discovery immediately followed by remote authentication or service creation is especially suspicious because it may indicate progression into lateral movement.<\/span><\/p>\n<p><b>Question 393.<\/b><\/p>\n<p><b>Which event most strongly indicates that discovery activity progressed into lateral movement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The source host authenticates to newly discovered servers and launches remote processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A DNS cache entry is created<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An NTP request is sent<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A DHCP lease is renewed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication to newly identified hosts followed by remote process execution strongly indicates lateral movement. The sequence suggests that discovery was used to select targets and that valid credentials or remote services were then used to expand access. Analysts should review the accounts used, logon types, destination processes, service creation, and any payload transfers. DNS, NTP, and DHCP are normal infrastructure activities and do not demonstrate lateral movement. Sequence and correlation are crucial for understanding attacker progression.<\/span><\/p>\n<p><b>Question 394.<\/b><\/p>\n<p><b>An analyst observes bulk access to confidential files followed by creation of a large encrypted archive. Which attacker activity is most likely occurring?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Defense Evasion only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Discovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Collection and staging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bulk access to confidential files followed by archive creation is consistent with Collection and staging. Attackers frequently consolidate gathered data into archives before transferring it externally because this simplifies transport and may obscure individual files. Analysts should identify the process responsible, user account, archive location, file types, and subsequent network activity. Legitimate backup or archival systems may show similar behavior, so business context matters. If the archive is later uploaded to an unusual external destination, confidence in an exfiltration hypothesis increases substantially.<\/span><\/p>\n<p><b>Question 395.<\/b><\/p>\n<p><b>Which network telemetry would best help determine whether the archive in the previous scenario was transferred externally?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NetFlow, firewall, proxy, or cloud-access telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> BIOS logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Monitor settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer queue records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Flow, firewall, proxy, and cloud-access logs can provide evidence of outbound transfer, including destination, timing, protocol, session duration, and byte counts. Analysts can correlate the transfer with the archive&#8217;s creation time and approximate size. Proxy or cloud telemetry may provide additional information about the specific service used. Endpoint telemetry can identify which process initiated the upload. BIOS and printer information are unrelated. Host and network correlation is the best way to establish whether staged data actually left the organization.<\/span><\/p>\n<p><b>Question 396.<\/b><\/p>\n<p><b>Which forensic concept should guide whether RAM is collected before disk data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Segmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Normalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Order of volatility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Order of volatility prioritizes evidence based on how quickly it can change or disappear. RAM and active network state are highly volatile and may vanish immediately when a system is powered off, while disk data is more persistent. Investigators use this principle to decide what to collect first, while still considering the urgency of containment. Least privilege, segmentation, and normalization are important security concepts but do not define forensic collection priority. Proper application of order of volatility helps preserve evidence that might otherwise be permanently lost.<\/span><\/p>\n<p><b>Question 397.<\/b><\/p>\n<p><b>Which forensic control helps ensure that original storage media is not altered during evidence acquisition?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Write blocker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> SIEM rule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Proxy server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Load balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A write blocker prevents the acquisition workstation from writing data back to the original storage device. This helps preserve timestamps, metadata, file-system structures, and deleted-file artifacts. It is commonly used during forensic imaging and should be combined with cryptographic hashing, secure evidence storage, and chain-of-custody documentation. SIEM rules, proxies, and load balancers perform unrelated functions. Investigators should normally analyze verified copies rather than original evidence so the source remains preserved.<\/span><\/p>\n<p><b>Question 398.<\/b><\/p>\n<p><b>A compromised endpoint is actively using a stolen privileged account to access additional servers. What should the response team prioritize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait until the next maintenance window<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Contain the endpoint and restrict the compromised identity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all identity logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable endpoint telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When active lateral movement is occurring, containment should address both the compromised system and the stolen identity. Isolating the endpoint can stop further network activity, while restricting or disabling the account and revoking active sessions can prevent continued authentication. The exact actions should follow organizational procedures and consider business impact. Waiting allows the attacker more time to expand access, while deleting logs or disabling telemetry removes visibility. After containment, analysts should determine which systems were already accessed and proceed with eradication.<\/span><\/p>\n<p><b>Question 399.<\/b><\/p>\n<p><b>Which task belongs primarily to the eradication phase after the active compromise has been contained?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing malware, persistence, compromised credentials, and exploited weaknesses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Conducting the final lessons-learned meeting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reconnecting affected systems immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling security monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication removes attacker footholds and addresses root causes. This includes removing malicious files and services, deleting unauthorized accounts or scheduled tasks, resetting compromised credentials, revoking tokens, and patching exploited vulnerabilities. Containment only limits immediate activity; it does not eliminate the threat. Recovery should begin only after the organization has reasonable confidence that malicious access has been removed. Lessons learned occurs later, and disabling monitoring would undermine the response.<\/span><\/p>\n<p><b>Question 400.<\/b><\/p>\n<p><b>A post-incident review finds that analysts identified the attack quickly but took too long to connect endpoint alerts with identity events and network activity. Which improvement would provide the most value?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce log retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable cross-platform detections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Improve normalization, correlation, and automated enrichment across endpoint, identity, and network telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove user context from alerts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When telemetry already exists but analysts struggle to connect it quickly, improved normalization and correlation can substantially reduce investigation time. Common fields such as username, hostname, IP address, process ID, timestamps, and device identifiers make it easier to link identity events with endpoint and network activity. Automated enrichment can add asset criticality, reputation, account privilege, recent alerts, and related sessions before an analyst begins manual investigation. Reducing retention or removing user context would make response slower and less accurate. Post-incident improvements should focus on turning fragmented telemetry into a coherent and repeatable investigation workflow.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP CyberSecurity 300-215 Exam Dumps and Practice Test Dumps &nbsp; Question 381. A SOC analyst observes an account successfully authenticating to a critical server from a host that was recently isolated for malware activity. What should the analyst do first? Investigate whether the credentials were compromised and whether the session is still [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23804"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23804"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23804\/revisions"}],"predecessor-version":[{"id":23805,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23804\/revisions\/23805"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}