300-215 exam dumps

300-215 practice question 119 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 119

Select 3

You are a cybersecurity analyst reviewing alerts in a Security Information and Event Management (SIEM) system. An IDS alert indicates a potential SQL injection attack targeting your web application server, while syslogs from the same server show several failed login attempts from the same IP address. What is the most likely course of action you should take to investigate and respond to this incident?

  1. A

    Correlate the IDS alert with syslog data to confirm if the same IP address is involved in both events.

  2. B

    Ignore the IDS alert since failed login attempts are unrelated to SQL injection attacks.

  3. C

    Capture the traffic from the suspect IP address using packet capture tools for deeper analysis.

  4. D

    Immediately block the IP address on the firewall without further investigation.

  5. E

    Review historical SIEM logs to check if the suspect IP address has triggered alerts in the past.

Show answer and explanation

Correct answers: A, C, E

Explanation

The correct actions involve investigating the incident thoroughly by correlating data from multiple sources (e.g., IDS alerts and syslogs), capturing network traffic for deeper analysis, and reviewing historical SIEM logs for patterns of past activity. These steps help confirm if the suspect IP address is involved in malicious behavior and collect sufficient evidence for an appropriate response. Blocking the IP address prematurely without adequate investigation or ignoring potential indicators of compromise are poor practices in incident response.

  • A. Correct.

    Correlating the IDS alert with syslog data can help identify if the same IP address is involved across multiple suspicious activities, which strengthens the case for further investigation.

  • B. Incorrect.

    Ignoring the IDS alert is not advised, as the failed login attempts and the SQL injection alert could be part of a coordinated attack from the same threat actor.

  • C. Correct.

    Capturing network traffic from the suspect IP address provides additional evidence and details about the attack, such as payloads or commands being sent to the server.

  • D. Incorrect.

    Blocking the IP address immediately without investigation may result in a false positive or disrupt legitimate traffic. A proper investigation is necessary to confirm malicious activity.

  • E. Correct.

    Reviewing historical SIEM logs helps identify if the suspect IP address has been involved in previous malicious activities, providing further context and evidence for response measures.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam