300-215 Pre-Exam Practice Tests (Updated 60 Questions) [Q35-Q58]

Share

300-215 Pre-Exam Practice Tests | (Updated 60 Questions)

Valid 300-215 Exam Q&A PDF - One Year Free Update

NEW QUESTION 35
An incident response team is recommending changes after analyzing a recent compromise in which:
a large number of events and logs were involved;
team members were not able to identify the anomalous behavior and escalate it in a timely manner; several network systems were affected as a result of the latency in detection; security engineers were able to mitigate the threat and bring systems back to a stable state; and the issue reoccurred shortly after and systems became unstable again because the correct information was not gathered during the initial identification phase.
Which two recommendations should be made for improving the incident response process? (Choose two.)

  • A. Formalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
  • B. Improve the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
  • C. Implement an automated operation to pull systems events/logs and bring them into an organizational context.
  • D. Allocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.
  • E. Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.

Answer: C,E

 

NEW QUESTION 36
Refer to the exhibit.

Which type of code created the snippet?

  • A. Bash Script
  • B. VB Script
  • C. PowerShell
  • D. Python

Answer: B

 

NEW QUESTION 37
What is the goal of an incident response plan?

  • A. to identify critical systems and resources in an organization
  • B. to contain an attack and prevent it from spreading
  • C. to determine security weaknesses and recommend solutions
  • D. to ensure systems are in place to prevent an attack

Answer: B

 

NEW QUESTION 38
Which information is provided bout the object file by the "-h" option in the objdump line command objdump -b oasys -m vax -h fu.o?

  • A. debugging
  • B. bfdname
  • C. help
  • D. headers

Answer: D

 

NEW QUESTION 39
Refer to the exhibit.

What should be determined from this Apache log?

  • A. The certificate file has been maliciously modified
  • B. The SSL traffic setup is improper
  • C. The private key does not match with the SSL certificate.
  • D. A module named mod_ssl is needed to make SSL connections.

Answer: B

 

NEW QUESTION 40

Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

  • A. Domain name:iraniansk.com
  • B. filename= "Fy.exe"
  • C. Server: nginx
  • D. Hash value: 5f31ab113af08=1597090577
  • E. Content-Type: application/octet-stream

Answer: D,E

 

NEW QUESTION 41
An "unknown error code" is appearing on an ESXi host during authentication. An engineer checks the authentication logs but is unable to identify the issue. Analysis of the vCenter agent logs shows no connectivity errors. What is the next log file the engineer should check to continue troubleshooting this error?

  • A. var/log/shell.log
  • B. /var/log/syslog.log
  • C. /var/log/vmksummary.log
  • D. var/log/general/log

Answer: B

 

NEW QUESTION 42
An attacker embedded a macro within a word processing file opened by a user in an organization's legal department. The attacker used this technique to gain access to confidential financial dat a. Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)

  • A. firewall rules creation
  • B. network access control
  • C. signed macro requirements
  • D. controlled folder access
  • E. removable device restrictions

Answer: C,D

 

NEW QUESTION 43
Refer to the exhibit.

A company that uses only the Unix platform implemented an intrusion detection system. After the initial configuration, the number of alerts is overwhelming, and an engineer needs to analyze and classify the alerts. The highest number of alerts were generated from the signature shown in the exhibit. Which classification should the engineer assign to this event?

  • A. True Negative alert
  • B. False Negative alert
  • C. False Positive alert
  • D. True Positive alert

Answer: C

 

NEW QUESTION 44
An "unknown error code" is appearing on an ESXi host during authentication. An engineer checks the authentication logs but is unable to identify the issue. Analysis of the vCenter agent logs shows no connectivity errors. What is the next log file the engineer should check to continue troubleshooting this error?

  • A. var/log/shell.log
  • B. /var/log/syslog.log
  • C. /var/log/vmksummary.log
  • D. var/log/general/log

Answer: B

Explanation:
Explanation/Reference: https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.monitoring.doc/GUID-
832A2618-6B11-4A28-9672-93296DA931D0.html

 

NEW QUESTION 45
What are YARA rules based upon?

  • A. HTML code
  • B. IP addresses
  • C. binary patterns
  • D. network artifacts

Answer: C

Explanation:
Explanation/Reference: https://en.wikipedia.org/wiki/YARA#:~:text=YARA%20is%20the%20name%20of,strings%20and
%20a%20boolean%20expression.

 

NEW QUESTION 46
Refer to the exhibit.

Which type of code is being used?

  • A. Python
  • B. BASH
  • C. Shell
  • D. VBScript

Answer: A

 

NEW QUESTION 47
Refer to the exhibit.

An employee notices unexpected changes and setting modifications on their workstation and creates an incident ticket. A support specialist checks processes and services but does not identify anything suspicious. The ticket was escalated to an analyst who reviewed this event log and also discovered that the workstation had multiple large data dumps on network shares. What should be determined from this information?

  • A. log tampering
  • B. reconnaissance attack
  • C. data obfuscation
  • D. brute-force attack

Answer: B

 

NEW QUESTION 48
An investigator is analyzing an attack in which malicious files were loaded on the network and were undetected. Several of the images received during the attack include repetitive patterns. Which anti-forensic technique was used?

  • A. spoofing
  • B. obfuscation
  • C. steganography
  • D. tunneling

Answer: C

 

NEW QUESTION 49
Drag and drop the capabilities on the left onto the Cisco security solutions on the right.

Answer:

Explanation:

 

NEW QUESTION 50
A network host is infected with malware by an attacker who uses the host to make calls for files and shuttle traffic to bots. This attack went undetected and resulted in a significant loss. The organization wants to ensure this does not happen in the future and needs a security solution that will generate alerts when command and control communication from an infected device is detected. Which network security solution should be recommended?

  • A. Cisco Secure Web Appliance (WSA)
  • B. Cisco Secure Firewall Threat Defense (Firepower)
  • C. Cisco Secure Firewall ASA
  • D. Cisco Secure Email Gateway (ESA)

Answer: B

 

NEW QUESTION 51
What is a use of TCPdump?

  • A. to analyze IP and other packets
  • B. to change IP ports
  • C. to view encrypted data fields
  • D. to decode user credentials

Answer: A

 

NEW QUESTION 52
An employee receives an email from a "trusted" person containing a hyperlink that is malvertising. The employee clicks the link and the malware downloads. An information analyst observes an alert at the SIEM and engages the cybersecurity team to conduct an analysis of this incident in accordance with the incident response plan. Which event detail should be included in this root cause analysis?

  • A. alarm raised by the SIEM
  • B. information from the email header
  • C. phishing email sent to the victim
  • D. alert identified by the cybersecurity team

Answer: A

 

NEW QUESTION 53
An engineer received a call to assist with an ongoing DDoS attack. The Apache server is being targeted, and availability is compromised. Which step should be taken to identify the origin of the threat?

  • A. An engineer should check the server's processes by running commands ps -aux and sudo ps -a.
  • B. An engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/ log/apache2/access.log.
  • C. An engineer should check the services on the machine by running the command service -status-all.
  • D. An engineer should check the list of usernames currently logged in by running the command $ who | cut - d' ' -f1| sort | uniq

Answer: B

 

NEW QUESTION 54
Refer to the exhibit.

After a cyber attack, an engineer is analyzing an alert that was missed on the intrusion detection system. The attack exploited a vulnerability in a business critical, web-based application and violated its availability. Which two migration techniques should the engineer recommend? (Choose two.)

  • A. address space randomization
  • B. encapsulation
  • C. data execution prevention
  • D. heap-based security
  • E. NOP sled technique

Answer: A,C

 

NEW QUESTION 55
Refer to the exhibit.

According to the SNORT alert, what is the attacker performing?

  • A. brute-force attack against directories and files on the target webserver
  • B. brute-force attack against the web application user accounts
  • C. SQL injection attack against the target webserver
  • D. XSS attack against the target webserver

Answer: A

 

NEW QUESTION 56
An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?

  • A. Investigate the sender of the email and communicate with the employee to determine the motives.
  • B. Monitor processes as this a standard behavior of Word macro embedded documents.
  • C. Upload the file signature to threat intelligence tools to determine if the file is malicious.
  • D. Contain the threat for further analysis as this is an indication of suspicious activity.

Answer: C

 

NEW QUESTION 57
A security team received an alert of suspicious activity on a user's Internet browser. The user's anti-virus software indicated that the file attempted to create a fake recycle bin folder and connect to an external IP address. Which two actions should be taken by the security analyst with the executable file for further analysis? (Choose two.)

  • A. Evaluate the behavioral indicators in Cisco Secure Malware Analytics (Threat Grid).
  • B. Analyze the TCP/IP Streams in Cisco Secure Malware Analytics (Threat Grid).
  • C. Evaluate the process activity in Cisco Umbrella.
  • D. Analyze the Magic File type in Cisco Umbrella.
  • E. Network Exit Localization in Cisco Secure Malware Analytics (Threat Grid).

Answer: A,B

 

NEW QUESTION 58
......

Conducting Forensic Analysis & Incident Response Using Cisco Technologies for CyberOps Free Update Certification Sample Questions: https://www.vce4plus.com/Cisco/300-215-valid-vce-dumps.html

Trend for Cisco 300-215 pdf dumps before actual exam: https://drive.google.com/open?id=1PMtprGZC_A3OJGF9-zhOH8EvmJp_FRSf