300-215 exam dumps

300-215 practice question 61 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 61

Single answer

During an investigation of a potential data breach, you are tasked with analyzing a compromised endpoint using Cisco Secure Endpoint. Which forensic technique should you prioritize to identify the malicious process responsible for the breach?

  1. A

    Review the file trajectory to trace the origin of the malicious file.

  2. B

    Analyze NetFlow data to identify external communication from the endpoint.

  3. C

    Capture and analyze a memory dump to identify active malicious processes.

  4. D

    Examine DNS query logs for suspicious domain names.

Show answer and explanation

Correct answer: C

Explanation

In this scenario, capturing and analyzing a memory dump is the most appropriate forensic technique to identify active malicious processes on the compromised endpoint. While other methods such as file trajectory analysis, NetFlow data, and DNS query logs can provide supporting evidence, they do not directly identify the processes responsible for the breach. Cisco Secure Endpoint and related tools enable analysts to extract and examine memory data for this purpose efficiently.

  • A. Incorrect.

    Reviewing the file trajectory helps trace the origin of a malicious file, but it does not directly identify the active malicious process responsible for the breach.

  • B. Incorrect.

    NetFlow data is useful for analyzing network traffic and identifying anomalous external communication but does not provide details about active processes on the endpoint.

  • C. Correct.

    Capturing and analyzing a memory dump allows you to identify active malicious processes running on the endpoint and is a critical forensic technique in this scenario.

  • D. Incorrect.

    Examining DNS query logs can reveal communication with suspicious domains but does not directly identify the malicious process on the endpoint.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam