300-215 exam dumps

300-215 practice question 175 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 175

Select 3

During an investigation of a cybersecurity incident, a forensic analyst observes that certain log files from a critical server are missing. Upon further inspection, it is discovered that the attacker used a tool to overwrite the logs with random data before deleting them. Which antiforensic techniques are most likely being used in this scenario?

  1. A

    Data destruction

  2. B

    Obfuscation

  3. C

    Geo location

  4. D

    Hindering forensics

  5. E

    Evading detection

Show answer and explanation

Correct answers: A, D, E

Explanation

In this scenario, the attacker employed multiple antiforensic techniques. By overwriting log files with random data, they used data destruction to ensure the logs could not be recovered. This also qualifies as hindering forensics because it actively obstructs the investigative process. Additionally, by removing evidence of their activities, the attacker aimed to evade detection by the forensic team.

  • A. Correct.

    Data destruction refers to the intentional removal or overwriting of data to prevent recovery, which matches the behavior observed in this scenario where logs were overwritten and deleted.

  • B. Incorrect.

    Obfuscation refers to making data difficult to understand or interpret but does not directly involve overwriting or deleting log files, so this is not applicable here.

  • C. Incorrect.

    Geo location involves identifying the physical location of a user or device and does not relate to the overwriting or deletion of log files.

  • D. Correct.

    Hindering forensics involves implementing strategies to make forensic analysis more difficult, such as overwriting logs to prevent investigators from obtaining useful information.

  • E. Correct.

    Evading detection involves taking measures to avoid being identified or tracked, such as destroying logs to prevent evidence of the attack from being found.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam