300-215 exam dumps

300-215 practice question 158 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 158

Select 4

A cybersecurity analyst at your organization is tasked with reviewing threat intelligence feeds to identify Indicators of Compromise (IOCs) and Indicators of Attack (IOAs). The analyst observes the following data in both internal and external feeds:

  1. A list of IP addresses flagged for hosting phishing websites.
  2. A sudden spike in failed login attempts from a specific geographic region.
  3. Malware hash values associated with recent ransomware campaigns.
  4. Behavioral patterns indicating lateral movement within the internal network.

Which of the following data points should the analyst classify as IOCs and IOAs?

  1. A

    The list of IP addresses flagged for hosting phishing websites (IOC)

  2. B

    The sudden spike in failed login attempts from a specific geographic region (IOA)

  3. C

    The malware hash values associated with recent ransomware campaigns (IOC)

  4. D

    The behavioral patterns indicating lateral movement within the internal network (IOA)

  5. E

    The list of employee emails used for phishing campaigns (IOC)

Show answer and explanation

Correct answers: A, B, C, D

Explanation

Threat intelligence feeds provide both IOCs and IOAs. IOCs are observable artifacts (e.g., IP addresses, file hashes) linked to malicious activity, whereas IOAs represent behaviors or patterns (e.g., lateral movement, login attempts) that indicate potential attacks. Analysts must classify data correctly to respond effectively to threats.

  • A. Correct.

    This is an IOC because IP addresses associated with malicious activities are observable artifacts that indicate compromise.

  • B. Correct.

    This is an IOA because the spike in failed login attempts represents a behavior that may indicate an ongoing or attempted attack.

  • C. Correct.

    This is an IOC because malware hash values are definitive artifacts that can be used to identify malicious files.

  • D. Correct.

    This is an IOA because lateral movement is a behavior indicating an active attack, often used to escalate privileges or spread malware within a network.

  • E. Incorrect.

    This is incorrect because while employee emails used in phishing campaigns may be tied to an attack, they are not definitive artifacts that classify as IOCs in this scenario.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam