300-215 exam dumps

300-215 practice question 116 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 116

Single answer

During a routine security operation, you receive an alert in your SIEM solution indicating a high volume of failed SSH login attempts to a critical server. The alert includes the following fields: Event Time, Source IP, Destination IP, Username, and Event Type. Upon reviewing the alert and associated logs, what should be your next step in interpreting this activity?

  1. A

    Investigate the source IP address to determine if it belongs to an internal or external network.

  2. B

    Immediately block the destination IP address in the firewall to prevent further attempts.

  3. C

    Analyze historical logs to identify if the source IP has been involved in previous suspicious activities.

  4. D

    Ignore the alert as it may be a benign false positive caused by a misconfigured service.

Show answer and explanation

Correct answer: A

Explanation

The next logical step in interpreting this activity is to investigate the source IP address to understand the origin of the failed login attempts. This information is critical to determine if the threat is external or internal and aids in prioritizing the level of response. While historical analysis and other actions may follow, identifying the source IP is the immediate priority in this context.

  • A. Correct.

    Correct. Investigating the source IP address helps determine the origin of the attack and whether it is internal or external, which is crucial for further response actions.

  • B. Incorrect.

    Incorrect. Blocking the destination IP (the critical server) would disrupt legitimate access and is not a logical step in this scenario.

  • C. Incorrect.

    Incorrect. While analyzing historical logs is a good practice, it is not the immediate next step in interpreting this specific alert.

  • D. Incorrect.

    Incorrect. Ignoring the alert could allow a potential brute force or dictionary attack to succeed, which is a significant security risk.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam