300-215 exam dumps

300-215 practice question 111 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 111

Select 2

During an incident response investigation, you are tasked with identifying lateral movement within the network. Using Cisco Secure Network Analytics (formerly Stealthwatch), which of the following actions would be most effective in identifying suspicious lateral movement activity?

  1. A

    Analyze host-to-host communication patterns for unusual traffic between internal hosts.

  2. B

    Review the Security Intelligence Events dashboard for external threats.

  3. C

    Inspect NetFlow data for an unusual number of connections originating from a single host.

  4. D

    Correlate alerts from Cisco Secure Endpoint for malware propagation activity.

  5. E

    Utilize the Cisco SecureX Threat Response tool to block identified malicious IP addresses.

Show answer and explanation

Correct answers: A, C

Explanation

Lateral movement detection requires analyzing internal network traffic patterns and behaviors. Cisco Secure Network Analytics provides capabilities to inspect host-to-host communications and NetFlow data for unusual activities, which are common indicators of lateral movement. Focusing on these activities helps responders identify compromised hosts and take appropriate action.

  • A. Correct.

    Analyzing host-to-host communication patterns is a key step in identifying lateral movement, as attackers often attempt to move between internal hosts to escalate privileges or access sensitive data.

  • B. Incorrect.

    Reviewing the Security Intelligence Events dashboard focuses on external threats and may not directly provide insights into lateral movement within the internal network.

  • C. Correct.

    Inspecting NetFlow data for an unusual number of connections from a single host can reveal potential lateral movement, as compromised hosts often attempt to connect to multiple other hosts in the network.

  • D. Incorrect.

    While correlating alerts from Cisco Secure Endpoint can help identify malware activity, it does not directly focus on detecting lateral movement within the network.

  • E. Incorrect.

    Using Cisco SecureX Threat Response to block malicious IPs is a containment action and does not contribute to identifying lateral movement within the internal network.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam