300-215 exam dumps

300-215 practice question 117 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 117

Single answer

You are investigating a potential incident involving unauthorized access to a critical server. The SIEM alert log indicates multiple failed authentication attempts followed by a successful login from an IP address located in a foreign country. The syslog from the server shows a high volume of file access activity immediately following the successful login. What should be your primary focus during the investigation?

  1. A

    Identify the geolocation and owner of the suspicious IP address.

  2. B

    Verify whether the successful login originated from a known user or service account.

  3. C

    Analyze the IDS/IPS logs to check for suspicious activity from the identified IP address.

  4. D

    Review the server's file access logs for unauthorized data exfiltration.

Show answer and explanation

Correct answer: B

Explanation

The primary focus during the investigation should be determining whether the successful login was authorized or unauthorized. This step helps establish whether the activity is part of a legitimate process or a security incident. Once this is determined, investigators can then proceed to analyze additional logs, such as IDS/IPS or file access logs, for further evidence of malicious activity, if needed.

  • A. Incorrect.

    While identifying the geolocation and owner of the suspicious IP address is useful, it does not directly address whether the login was authorized or unauthorized, which is critical to the investigation.

  • B. Correct.

    Verifying whether the successful login originated from a known user or service account is key to determining if the login was legitimate or part of unauthorized access.

  • C. Incorrect.

    Analyzing the IDS/IPS logs for suspicious activity is a valid step, but it should come after confirming the legitimacy of the login and understanding the initial access vector.

  • D. Incorrect.

    Reviewing the server's file access logs for unauthorized data exfiltration is important but should be done after confirming whether the login itself was authorized.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam