[Sep-2021] Updated CyberOps Professional 300-215 Exam Questions BUNDLE PACK [Q28-Q47]

Share

[Sep-2021] Updated CyberOps Professional 300-215 Exam Questions BUNDLE PACK

Master The Cisco Content 300-215 EXAM DUMPS WITH GUARANTEED SUCCESS!

NEW QUESTION 28
A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)

  • A. Inspect PE header.
  • B. Inspect file hash.
  • C. Inspect processes.
  • D. Inspect registry entries
  • E. Inspect file type.

Answer: B,C

Explanation:
Explanation/Reference: https://medium.com/@Flying_glasses/top-5-ways-to-detect-malicious-file-manually- d02744f7c43a

 

NEW QUESTION 29
An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?

  • A. Investigate the sender of the email and communicate with the employee to determine the motives.
  • B. Monitor processes as this a standard behavior of Word macro embedded documents.
  • C. Upload the file signature to threat intelligence tools to determine if the file is malicious.
  • D. Contain the threat for further analysis as this is an indication of suspicious activity.

Answer: C

 

NEW QUESTION 30
An attacker embedded a macro within a word processing file opened by a user in an organization's legal department. The attacker used this technique to gain access to confidential financial dat a. Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)

  • A. firewall rules creation
  • B. network access control
  • C. signed macro requirements
  • D. controlled folder access
  • E. removable device restrictions

Answer: C,D

 

NEW QUESTION 31
A security team received reports of users receiving emails linked to external or unknown URLs that are non- returnable and non-deliverable. The ISP also reported a 500% increase in the amount of ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)

  • A. scan hosts with updated signatures
  • B. verify the breadth of the attack
  • C. collect logs
  • D. remove vulnerabilities
  • E. request packet capture

Answer: A,D

 

NEW QUESTION 32

Refer to the exhibit. A security analyst notices unusual connections while monitoring traffic. What is the attack vector, and which action should be taken to prevent this type of event?

  • A. DNS spoofing; encrypt communication protocols
  • B. SYN flooding, block malicious packets
  • C. ARP spoofing; configure port security
  • D. MAC flooding; assign static entries

Answer: C

 

NEW QUESTION 33
Which technique is used to evade detection from security products by executing arbitrary code in the address space of a separate live operation?

  • A. GPO modification
  • B. process injection
  • C. token manipulation
  • D. privilege escalation

Answer: B

Explanation:
Explanation/Reference: https://attack.mitre.org/techniques/T1055/

 

NEW QUESTION 34
Drag and drop the cloud characteristic from the left onto the challenges presented for gathering evidence on the right.

Answer:

Explanation:

 

NEW QUESTION 35

Refer to the exhibit. After a cyber attack, an engineer is analyzing an alert that was missed on the intrusion detection system. The attack exploited a vulnerability in a business critical, web-based application and violated its availability. Which two migration techniques should the engineer recommend? (Choose two.)

  • A. address space randomization
  • B. encapsulation
  • C. data execution prevention
  • D. heap-based security
  • E. NOP sled technique

Answer: A,C

 

NEW QUESTION 36
Refer to the exhibit.

Which element in this email is an indicator of attack?

  • A. content-Type: multipart/mixed
  • B. subject: "Service Credit Card"
  • C. attachment: "Card-Refund"
  • D. IP Address: 202.142.155.218

Answer: C

 

NEW QUESTION 37
Refer to the exhibit.

A company that uses only the Unix platform implemented an intrusion detection system. After the initial configuration, the number of alerts is overwhelming, and an engineer needs to analyze and classify the alerts. The highest number of alerts were generated from the signature shown in the exhibit. Which classification should the engineer assign to this event?

  • A. True Negative alert
  • B. False Negative alert
  • C. False Positive alert
  • D. True Positive alert

Answer: C

 

NEW QUESTION 38
A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)

  • A. Inspect PE header.
  • B. Inspect file hash.
  • C. Inspect processes.
  • D. Inspect registry entries
  • E. Inspect file type.

Answer: B,C

 

NEW QUESTION 39

Refer to the exhibit. According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

  • A. Domain name:iraniansk.com
  • B. filename= "Fy.exe"
  • C. Server: nginx
  • D. Hash value: 5f31ab113af08=1597090577
  • E. Content-Type: application/octet-stream

Answer: D,E

 

NEW QUESTION 40
A website administrator has an output of an FTP session that runs nightly to download and unzip files to a local staging server. The download includes thousands of files, and the manual process used to find how many files failed to download is time-consuming. The administrator is working on a PowerShell script that will parse a log file and summarize how many files were successfully downloaded versus ones that failed. Which script will read the contents of the file one line at a time and return a collection of objects?

  • A. Get-Content-Folder \\Server\FTPFolder\Logfiles\ftpfiles.log | Show-From "ERROR", "SUCCESS"
  • B. Get-Content -Path \\Server\FTPFolder\Logfiles\ftpfiles.log | Select-String "ERROR", "SUCCESS"
  • C. Get-Content -Directory \\Server\FTPFolder\Logfiles\ftpfiles.log | Export-Result "ERROR", "SUCCESS"
  • D. Get-Content -ifmatch \\Server\FTPFolder\Logfiles\ftpfiles.log | Copy-Marked "ERROR", "SUCCESS"

Answer: B

 

NEW QUESTION 41
An organization recovered from a recent ransomware outbreak that resulted in significant business damage. Leadership requested a report that identifies the problems that triggered the incident and the security team's approach to address these problems to prevent a reoccurrence. Which components of the incident should an engineer analyze first for this report?

  • A. motive and factors
  • B. cause and effect
  • C. risk and RPN
  • D. impact and flow

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 42
Refer to the exhibit.

Which two actions should be taken as a result of this information? (Choose two.)

  • A. Block all emails with pdf attachments.
  • B. Block all emails with subject containing "cf2b3ad32a8a4cfb05e9dfc45875bd70".
  • C. Update the AV to block any file with hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
  • D. Block all emails sent from an @state.gov address.
  • E. Block emails sent from [email protected] with an attached pdf file with md5 hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".

Answer: C,D

 

NEW QUESTION 43
A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file's behavior. Which logs should be reviewed next to evaluate this file further?

  • A. email security appliance
  • B. Antivirus solution
  • C. network device
  • D. DNS server

Answer: D

 

NEW QUESTION 44
Refer to the exhibit.

An engineer is analyzing a TCP stream in a Wireshark after a suspicious email with a URL. What should be determined about the SMB traffic from this stream?

  • A. It is exploiting redirect vulnerability
  • B. It is requesting authentication on the user site.
  • C. It is redirecting to a malicious phishing website,
  • D. It is sharing access to files and printers.

Answer: A

 

NEW QUESTION 45
Which tool conducts memory analysis?

  • A. MemDump
  • B. Sysinternals Autoruns
  • C. Volatility
  • D. Memoryze

Answer: C

 

NEW QUESTION 46
Refer to the exhibit.

Which determination should be made by a security analyst?

  • A. An email was sent with an attachment named "Final Report.doc".
  • B. An email was sent with an attachment named "Grades.doc.exe".
  • C. An email was sent with an attachment named "Final Report.doc.exe".
  • D. An email was sent with an attachment named "Grades.doc".

Answer: C

 

NEW QUESTION 47
......

Pass Cisco 300-215 Exam – Experts Are Here To Help You: https://www.braindumpspass.com/Cisco/300-215-practice-exam-dumps.html

Get Latest CyberOps Professional 300-215 Practice Test For Quick Preparation: https://drive.google.com/open?id=1XZBt2I2MNTlu0unCTszcTI2YbnVhOAD-