Free 300-215 sample questions
Real questions from the Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity (CBRFIR) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A security team receives an alert from Cisco Secure Cloud Analytics (Stealthwatch Cloud) for an AWS EC2 instance. The alert, 'Anomalous RDP Brute Force,' indicates the instance is receiving an unusually high number of inbound RDP connection attempts from multiple external IP addresses. Which TWO actions are appropriate mitigation steps? (Select TWO) graph TD subgraph Internet Attacker1 Attacker2 Attacker3 end subgraph AWS_VPC SG[Security Group] EC2[EC2 Instance] end Attacker1 -->|RDP Port 3389| SG Attacker2 -->|RDP Port 3389| SG Attacker3 -->|RDP Port 3389| SG SG -->> EC2
A SOC has received a high-fidelity alert from Cisco Secure Endpoint indicating that a process, `svchost.exe`, has initiated a network connection to a known malicious IP address. The endpoint is a critical database server. Using a SOAR platform integrated with the Cisco security suite, what is the most appropriate and immediate automated mitigation action to recommend?
A SOC uses Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) to monitor its AWS environment. An alert is generated for 'Anomalous Port Usage' from an EC2 instance that typically only communicates over TCP/443. The new traffic is a long-lived connection over TCP/6667. What is the most likely cause of this alert?
A security team receives an alert from Cisco Secure Cloud Analytics (Stealthwatch Cloud) indicating that an EC2 instance in their AWS environment is making numerous outbound RDP connections to multiple external IP addresses. Which TWO actions should be taken to mitigate this threat and improve the security posture? (Select TWO)
During a memory forensics investigation of a Windows system using Volatility, an analyst suspects a process hollowing attack. Which plugin should be used to compare the Process Environment Block (PEB) in-memory structure against the on-disk executable to identify this specific type of injection?
A SOC analyst is reviewing Cisco Secure Network Analytics (Stealthwatch) alerts and notices a host exhibiting a 'Custom Security Event - High Concern Index' alarm. The host is making numerous small outbound connections to various IP addresses on non-standard ports, a pattern inconsistent with its baseline behavior. This behavior is indicative of which stage of an attack?
An incident responder is creating a YARA rule to detect a specific malware family that uses a custom XOR encoding routine on its configuration strings. To improve the rule's resilience against minor malware variants, which two sections should be included? (Choose two.)
A financial institution is implementing a new incident response playbook for handling fileless malware attacks that leverage PowerShell. The primary detection tool is Cisco Secure Endpoint, which logs all process command-line arguments. The playbook needs to define a clear, immediate containment step upon detecting a suspicious PowerShell command. Which action is the most effective and appropriate first containment step?
True or False: When performing forensic analysis on a Cisco ASA firewall, the output of `show conn detail` is considered volatile evidence and must be captured before the device is powered down or the connection is terminated.
10 more free samples are waiting
Create a free account to unlock the whole 300-215 sample bank, or get full access to all 232 practice questions in the simulator.