Cisco® 300-215 Exam Practice Questions (P. 1)
- Full Access (117 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
                                    A security team is discussing lessons learned and suggesting process changes after a security breach incident. During the incident, members of the security team failed to report the abnormal system activity due to a high project workload. Additionally, when the incident was identified, the response took six hours due to management being unavailable to provide the approvals needed. Which two steps will prevent these issues from occurring in the future? (Choose two.)
                                
                              - AIntroduce a priority rating for incident response workloads.
- BProvide phishing awareness training for the fill security team.
- CConduct a risk audit of the incident response workflow.
- DCreate an executive team delegation plan.
- EAutomate security alert timeframes with escalation triggers.
                                        Correct Answer:
AE
                                        
                                        
                                            
                                        
                                    
                                   
                                    AE
          
          send
        
        
          light_mode
          delete
      
    Question #2
                                    An engineer is investigating a ticket from the accounting department in which a user discovered an unexpected application on their workstation. Several alerts are seen from the intrusion detection system of unknown outgoing internet traffic from this workstation. The engineer also notices a degraded processing capability, which complicates the analysis process. Which two actions should the engineer take? (Choose two.)
                                
                              - ARestore to a system recovery point.
- BReplace the faulty CPU.
- CDisconnect from the network.
- DFormat the workstation drives.
- ETake an image of the workstation.
                                        Correct Answer:
AE
                                        
                                        
                                            
                                        
                                    
                                   
                                    AE
          
          send
        
        
          light_mode
          delete
      
    Question #3

Refer to the exhibit. What should an engineer determine from this Wireshark capture of suspicious network traffic?
- AThere are signs of SYN flood attack, and the engineer should increase the backlog and recycle the oldest half-open TCP connections.
- BThere are signs of a malformed packet attack, and the engineer should limit the packet size and set a threshold of bytes as a countermeasure.
- CThere are signs of a DNS attack, and the engineer should hide the BIND version and restrict zone transfers as a countermeasure.
- DThere are signs of ARP spoofing, and the engineer should use Static ARP entries and IP address-to-MAC address mappings as a countermeasure.
                                        Correct Answer:
A
                                        
                                        
                                            
                                        
                                    
                                   
                                    A
          
          send
        
        
          light_mode
          delete
      
    Question #4

Refer to the exhibit. A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?
- Ahttp.request.un matches
- Btls.handshake.type ==1
- Ctcp.port eq 25
- Dtcp.window_size ==0
                                        Correct Answer:
B
Reference:
https://www.malware-traffic-analysis.net/2018/11/08/index.html https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/
                                   
                                    B
Reference:
https://www.malware-traffic-analysis.net/2018/11/08/index.html https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/
          
          send
        
        
          light_mode
          delete
      
    Question #5
                                    What is a concern for gathering forensics evidence in public cloud environments?
                                
                              - AHigh Cost: Cloud service providers typically charge high fees for allowing cloud forensics.
- BConfiguration: Implementing security zones and proper network segmentation.
- CTimeliness: Gathering forensics evidence from cloud service providers typically requires substantial time.
- DMultitenancy: Evidence gathering must avoid exposure of data from other tenants.
                                        Correct Answer:
D
Reference:
https://www.researchgate.net/publication/307871954_About_Cloud_Forensics_Challenges_and_Solutions
                                   
                                    D
Reference:
https://www.researchgate.net/publication/307871954_About_Cloud_Forensics_Challenges_and_Solutions
          
          send
        
        
          light_mode
          delete
      
    All Pages
