300-215 exam dumps

300-215 practice question 71 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 71

Select 3

During a forensic investigation on a compromised host, you suspect that malicious activity occurred through unauthorized user logins and changes to critical system files. Which files should you retrieve, and where are they typically located on the host?

  1. A

    System event logs located in /var/log/syslog or C:\Windows\System32\winevt\Logs\System.evtx

  2. B

    User authentication logs located in /var/log/auth.log or C:\Windows\System32\winevt\Logs\Security.evtx

  3. C

    Temporary internet files located in the user's browser cache directory

  4. D

    Application-specific logs located in /var/log/application_name.log or the application's installation directory

  5. E

    Kernel debug logs located in /proc/kmsg

Show answer and explanation

Correct answers: A, B, D

Explanation

For a forensic investigation targeting unauthorized logins and changes to critical system files, gathering system event logs, user authentication logs, and application-specific logs is essential. These logs provide a comprehensive view of system and user activities that are critical for identifying suspicious behavior. Temporary internet files and kernel debug logs may have limited relevance in this specific scenario.

  • A. Correct.

    System event logs provide a record of system-level events, such as system reboots or service errors. These logs are critical for identifying potential malicious actions impacting the system and are typically stored in /var/log/syslog (Linux) or System.evtx (Windows).

  • B. Correct.

    User authentication logs record login attempts and user authentication details. These logs are essential for identifying unauthorized login attempts or privilege escalations. They are typically located in /var/log/auth.log (Linux) or Security.evtx (Windows).

  • C. Incorrect.

    Temporary internet files may contain evidence of browsing activity but are not typically critical for identifying unauthorized system logins or changes to critical system files.

  • D. Correct.

    Application-specific logs may capture information about specific software running on the system, including potential errors or malicious activity. These logs are located in /var/log/application_name.log (Linux) or within the application's installation directory.

  • E. Incorrect.

    Kernel debug logs (e.g., /proc/kmsg) are useful for diagnosing kernel-level issues but are not typically relevant for identifying unauthorized user logins or changes to critical system files.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam