300-215 exam dumps

300-215 practice question 64 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 64

Select 3

During a forensic investigation, you are tasked with analyzing network traffic using Cisco Secure Network Analytics (formerly Stealthwatch) to identify an ongoing data exfiltration attempt. Which of the following forensic techniques should you prioritize to accurately detect and analyze the malicious activity?

  1. A

    Review flow records to identify abnormal traffic patterns, such as large data transfers to external IPs.

  2. B

    Enable NetFlow on all endpoints to capture full packet data for deep inspection.

  3. C

    Correlate flow records with threat intelligence feeds to identify known malicious IP addresses.

  4. D

    Configure baselines for normal network behavior to detect deviations in traffic patterns.

  5. E

    Deploy endpoint agents to capture memory dumps for analysis of malicious processes.

Show answer and explanation

Correct answers: A, C, D

Explanation

To detect and analyze data exfiltration using Cisco Secure Network Analytics, forensic techniques such as reviewing flow records, correlating with threat intelligence feeds, and establishing network traffic baselines are crucial. These methods allow investigators to identify deviations in traffic patterns and detect potential threats without requiring full packet capture or endpoint-level analysis.

  • A. Correct.

    Reviewing flow records is a key forensic technique in Cisco Secure Network Analytics. This can help identify unusual traffic patterns, such as large volumes of data being sent to external IPs, which could indicate data exfiltration.

  • B. Incorrect.

    While NetFlow provides valuable metadata about network traffic, it does not capture full packet data. Full packet capture is not the primary focus of Cisco Secure Network Analytics and is not feasible or necessary for initial detection of data exfiltration.

  • C. Correct.

    Correlating flow records with threat intelligence feeds is an effective technique to identify suspicious or known malicious IPs involved in the data exfiltration.

  • D. Correct.

    Establishing baselines for normal network behavior allows you to detect anomalies, which is essential for identifying deviations that might indicate malicious activity like data exfiltration.

  • E. Incorrect.

    While endpoint agents and memory dumps are valuable for forensic analysis at the host level, they are not directly used in the context of network traffic analysis with Cisco Secure Network Analytics.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam