300-215 exam dumps

300-215 practice question 5 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 5

Single answer

A cybersecurity analyst is tasked with investigating suspicious activity on a company's network. During the investigation, the analyst uses Cisco Secure Network Analytics (formerly Stealthwatch) to identify unusual traffic patterns. Which fundamental concept of forensic analysis does this scenario primarily involve?

  1. A

    Baseline analysis

  2. B

    Chain of custody

  3. C

    Memory forensics

  4. D

    File integrity monitoring

Show answer and explanation

Correct answer: A

Explanation

Baseline analysis is a fundamental principle in cybersecurity forensic analysis. By leveraging Cisco Secure Network Analytics, the analyst is comparing current traffic behavior to a known baseline to detect deviations, such as unusual traffic patterns. This method helps in identifying potentially malicious activities on the network.

  • A. Correct.

    Baseline analysis involves comparing current network behavior against established normal patterns to identify anomalies, which is the primary concept being used in this scenario.

  • B. Incorrect.

    Chain of custody refers to the proper handling and documentation of evidence, which is unrelated to the activity described here.

  • C. Incorrect.

    Memory forensics involves analyzing volatile data from a system's memory, which is not applicable to the network traffic analysis described in this scenario.

  • D. Incorrect.

    File integrity monitoring focuses on detecting unauthorized changes to files and is unrelated to analyzing network traffic patterns.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam