300-215 exam dumps

300-215 practice question 75 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 75

Select 3

During a forensic investigation, you are tasked with collecting files related to a suspicious PowerShell script execution on a Windows host. Which files and their locations should you prioritize to gather evidence for further analysis?

  1. A

    PowerShell event logs located at C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Operational.evtx

  2. B

    Prefetch files located at C:\Windows\Prefetch

  3. C

    The Registry hive file located at C:\Windows\System32\config\SOFTWARE

  4. D

    The IIS web server logs located at C:\inetpub\logs\LogFiles

  5. E

    Windows firewall logs located at C:\Windows\System32\LogFiles\Firewall

Show answer and explanation

Correct answers: A, B, C

Explanation

To investigate suspicious PowerShell script execution, it is critical to collect files that provide insights into script execution (PowerShell event logs), execution timelines (Prefetch files), and potential persistence or configuration changes (Registry hives). These sources help reconstruct the incident comprehensively. Other logs, such as IIS and firewall logs, may be relevant for broader investigations but are not directly tied to PowerShell execution on the host.

  • A. Correct.

    PowerShell event logs provide detailed information about executed scripts, including command-line arguments and execution history, making it a critical source for investigating suspicious PowerShell activity.

  • B. Correct.

    Prefetch files can reveal information about recently executed programs, including PowerShell scripts, and are valuable for understanding execution timelines.

  • C. Correct.

    The SOFTWARE Registry hive contains configuration and persistence-related data, which may include entries modified or created by the suspicious PowerShell script.

  • D. Incorrect.

    IIS web server logs are unrelated to PowerShell activity unless the investigation involves a web server hosting malicious scripts. This is less relevant to the scenario described.

  • E. Incorrect.

    Windows firewall logs track network activity and potential connections, but they do not directly relate to the execution of PowerShell scripts on the host.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam