Cisco Conducting Forensic Analysis & Incident Response Using Cisco Technologies for CyberOps - 300-215 FREE EXAM DUMPS QUESTIONS & ANSWERS

Which tool should be used for dynamic malware analysis?
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A cybersecurity analyst must evaluate files from an endpoint in an enterprise network. The antivirus software on the endpoint flagged a suspicious file during a routine scan On initial evaluation the file did not match any known signatures in the antivirus database, but exhibited unusual network behavior during dynamic analysis Which step should the analyst take next?
Correct Answer: D Vote an answer
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
According to Cisco ISE best practices for MDM scenarios, what happens next after a user associates a device with an SSID?
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
An organization publishes a Microsoft Exchange Outlook Web App (OWA) server to provide access to enterprise email and deploys a web application firewall in front of it. Microsoft announces a newly discovered zero-day vulnerability that is being actively exploited. The vulnerability is triggered by a specially crafted request to an uncommonly used URL, and a patch is still being developed. Which action immediately protects the organization?
Correct Answer: A Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibit.

A security analyst reviews correlated DNS and TLS activity in a SIEM dashboard. What does the observed activity indicate about the host's behavior?
Correct Answer: D Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibit.

What do these artifacts indicate?
Correct Answer: A Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
An analyst finds .xyz files of unknown origin that are large and undetected by antivirus. What action should be taken next?
Correct Answer: D Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
An engineer is analyzing a ticket for an unexpected server shutdown and discovers that the web-server ran out of useable memory and crashed.
Which data is needed for further investigation?
Correct Answer: A Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Drag and drop the cloud characteristic from the left onto the challenges presented for gathering evidence on the right.
Correct Answer:

Refer to the exhibit.

A company was acquired by a larger organization, and the IT security team was asked to evaluate its security architecture. The main server had been compromised by ransomware seven months earlier but was subsequently recovered and reimaged by an incident-response company. After identifying inconsistencies in the report, the team requested all available server logs, extracted using a forensic script. Which two DLL files shown in the ListDLLs output require further investigation? (Choose two.)
Correct Answer: A,E Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
The Digital Forensics and Incident Response (DFIR) team notices many encrypted files on an endpoint. The team also determines that the threat uses stolen Remote Desktop Protocol (RDP) credentials. The DFIR team responds according to the internal incident-response playbook. Which two elements make up the containment phase for this incident? (Choose two.)
Correct Answer: A,D Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibit.

Which two actions should be taken as a result of this information? (Choose two.)
Correct Answer: A,C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
0
0
0
10