300-215 exam dumps

300-215 practice question 210 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 210

Select 4

A security operations team is tasked with creating an incident response playbook for potential ransomware attacks. Which of the following elements must be included to ensure an effective and comprehensive response?

  1. A

    Identification of critical assets and data to prioritize during an incident

  2. B

    A detailed inventory of all IT hardware across the organization

  3. C

    Clear escalation paths and communication plans during an incident

  4. D

    Procedures for evidence collection and chain of custody preservation

  5. E

    Details about daily monitoring thresholds for network traffic

  6. F

    Post-incident activities such as lessons learned and playbook updates

Show answer and explanation

Correct answers: A, C, D, F

Explanation

An effective incident response playbook must include elements that enable the team to detect, respond, and recover from incidents efficiently. Identifying critical assets (to prioritize protection), establishing clear communication paths, preserving evidence (for legal and forensic purposes), and planning post-incident activities (to improve future responses) are all critical components. While IT asset inventories and monitoring thresholds are useful for broader security practices, they do not directly address the core requirements of an incident response playbook.

  • A. Correct.

    Correct. Identifying critical assets and data is essential to prioritize response efforts and protect the most valuable resources during an incident.

  • B. Incorrect.

    Incorrect. While an IT hardware inventory is useful for general IT management, it is not a core element of an incident response playbook.

  • C. Correct.

    Correct. Escalation paths and communication plans ensure the right stakeholders are informed and response efforts are coordinated effectively.

  • D. Correct.

    Correct. Procedures for evidence collection and chain of custody preservation are critical for forensic analysis and potential legal proceedings.

  • E. Incorrect.

    Incorrect. Monitoring thresholds are part of routine security operations but are not a key element in incident response playbooks.

  • F. Correct.

    Correct. Post-incident activities like conducting a lessons-learned session and updating the playbook improve future response readiness.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam