300-215 exam dumps

300-215 practice question 12 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 12

Select 4

An organization suspects that a configuration change on a core network router might have been made by an unauthorized user. As part of the forensic analysis process, which of the following steps should you perform to gather evidence and analyze the incident?

  1. A

    Capture the device's running and startup configurations for comparison.

  2. B

    Check the device's syslog and SNMP logs for unusual activity.

  3. C

    Reboot the router to clear any potential malicious changes.

  4. D

    Retrieve the device's command history to identify unauthorized commands.

  5. E

    Analyze NetFlow data to identify suspicious traffic patterns associated with the router.

  6. F

    Reset the device to factory defaults to ensure no configuration changes persist.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

During forensic analysis of a network device, it's essential to gather and analyze evidence without altering or destroying it. Steps like capturing configurations, reviewing logs, retrieving command history, and analyzing traffic patterns are key to understanding the scope and nature of the incident. Actions like rebooting or resetting the device should be avoided as they can destroy crucial evidence.

  • A. Correct.

    Capturing the running and startup configurations allows you to compare them for any unauthorized or unexpected changes, which is a critical step in forensic analysis.

  • B. Correct.

    Examining the syslog and SNMP logs can help identify unusual activity, such as unauthorized access or configuration changes.

  • C. Incorrect.

    Rebooting the router can potentially destroy volatile evidence, such as command history or active sessions, and should generally be avoided during forensic analysis.

  • D. Correct.

    Retrieving the command history can provide insights into what commands were executed and help identify unauthorized activities.

  • E. Correct.

    Analyzing NetFlow data can reveal suspicious traffic patterns that might be linked to the incident, such as data exfiltration or unauthorized access attempts.

  • F. Incorrect.

    Resetting the device to factory defaults before completing the investigation would erase critical evidence and should never be done during forensic analysis.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam