300-215 exam dumps

300-215 practice question 185 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 185

Select 4

A cybersecurity analyst is investigating unusual activity on the network and uses NetFlow to identify abnormal traffic patterns. The analyst notices a significant amount of traffic from a single internal IP address to an unfamiliar external IP address on TCP port 4444. They then use Wireshark to capture and filter the traffic from this internal IP. Which of the following steps can help confirm if the activity is malicious?

  1. A

    Filter Wireshark traffic by the internal IP and analyze payloads for suspicious content, such as encoded commands or malware signatures.

  2. B

    Check the NetFlow records to identify if the external IP has communicated with other internal hosts.

  3. C

    Search for DNS queries in Wireshark to determine if the internal IP resolved the external IP before establishing the connection.

  4. D

    Use Wireshark to analyze the handshake process during the TCP session to confirm if the connection was encrypted.

  5. E

    Verify if the external IP address is listed in a known threat intelligence database.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

By combining network traffic analysis through NetFlow and detailed packet inspection using Wireshark, the analyst can identify signs of malicious activity. Filtering traffic, checking DNS queries, and correlating information with threat intelligence databases provide strong evidence of potential threats. While analyzing encryption in the handshake process offers some insight, it does not directly confirm malicious intent.

  • A. Correct.

    Filtering Wireshark traffic by the internal IP and analyzing payloads can reveal malicious content such as malware or encoded commands, which are common in attacks like remote access trojans (RATs).

  • B. Correct.

    NetFlow records can help determine if the external IP is targeting multiple internal hosts, which could indicate lateral movement or scanning activity.

  • C. Correct.

    DNS queries can provide evidence that the internal host resolved the external IP, potentially revealing the domain associated with malicious activity.

  • D. Incorrect.

    Analyzing the handshake process in Wireshark might provide information about encryption, but it does not directly confirm malicious activity.

  • E. Correct.

    Checking the external IP against a known threat intelligence database can confirm if it has been associated with malicious activities in the past.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam