300-215 exam dumps

300-215 practice question 122 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 122

Select 3

During an incident involving suspected malware propagation within a corporate network, you need to determine which data sources to correlate in order to identify the root cause and extent of the attack. Which of the following data sources should you prioritize to effectively correlate both host-based and network-based activities?

  1. A

    Endpoint logs from affected hosts

  2. B

    NetFlow data from network devices

  3. C

    DNS query logs

  4. D

    Threat intelligence feeds

  5. E

    Physical access logs for the data center

Show answer and explanation

Correct answers: A, B, C

Explanation

To effectively correlate host-based and network-based activities during an incident, it is essential to collect data that provides visibility into both aspects. Endpoint logs reveal activities occurring on the hosts, NetFlow data shows network traffic patterns, and DNS query logs can uncover malicious domain usage. These data sources together provide a comprehensive view of the incident, enabling you to trace the malware's activities and impact.

  • A. Correct.

    Endpoint logs from affected hosts are critical for identifying host-based activities such as malware execution, file modifications, or unauthorized processes.

  • B. Correct.

    NetFlow data from network devices provides insights into network-based activities such as unusual data transfers or connections to malicious IPs.

  • C. Correct.

    DNS query logs can help identify domain names that the malware may use for command-and-control communication or data exfiltration.

  • D. Incorrect.

    Threat intelligence feeds, while useful for general situational awareness, do not directly provide the specific correlation data required for this scenario.

  • E. Incorrect.

    Physical access logs are unrelated to this scenario, as the incident pertains to malware propagation and not unauthorized physical access.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam