300-215 Sample Questions & Answers
ThreatGrid-based incident-response playbooks make up the largest share, alongside interpreting alerts and correlating data about attack vectors, analyzing fileless malware and host files, antiforensic awareness, and forensic work on root causes and network devices.
Launch the full 300-215 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Forensics Techniques · Recognize purpose, use, and functionality of libraries and tools such as Volatility
During a memory forensics investigation of a Windows system using Volatility, an analyst suspects a process hollowing attack. Which plugin should be used to compare the Process Environment Block (PEB) in-memory structure against the on-disk executable to identify this specific type of injection?
Show answer & explanation
Correct answer: C
The
hollowfindplugin is specifically designed to detect process hollowing techniques. It scans for discrepancies between a process's in-memory data structures (like the PEB) and its corresponding on-disk file, which is the hallmark of this attack. - Question 2Intermediate
Incident Response Techniques · Interpret alert logs such as SIEM, IDS/IPS and syslogs
A SOC analyst is reviewing Cisco Secure Network Analytics (Stealthwatch) alerts and notices a host exhibiting a 'Custom Security Event - High Concern Index' alarm. The host is making numerous small outbound connections to various IP addresses on non-standard ports, a pattern inconsistent with its baseline behavior. This behavior is indicative of which stage of an attack?
Show answer & explanation
Correct answer: B
The pattern of numerous small, outbound connections to various IPs on non-standard ports is a classic indicator of C2 beaconing or scanning for a live C2 server. Cisco Secure Network Analytics excels at detecting such behavioral anomalies against a learned baseline of normal traffic.
- Question 3IntermediateSelect 2
Fundamentals · Describe the use and characteristics of YARA rules (basics) for malware identification
An incident responder is creating a YARA rule to detect a specific malware family that uses a custom XOR encoding routine on its configuration strings. To improve the rule's resilience against minor malware variants, which two sections should be included? (Choose two.)
Show answer & explanation
Correct answers: B, D
The decoding routine is often a stable piece of code across malware variants. Creating a signature based on the immutable byte patterns of this logic provides a highly resilient detection mechanism.
A strong condition, such as
(uint32(0) == 0x5A4D) and (2 of ($group1)) and (all of ($group2)), ensures that multiple pieces of evidence must be found. This significantly reduces false positives and makes the rule more reliable and resilient against simple changes. - Question 4Intermediate
Incident Response Processes · Evaluate elements required in an incident response playbook
A financial institution is implementing a new incident response playbook for handling fileless malware attacks that leverage PowerShell. The primary detection tool is Cisco Secure Endpoint, which logs all process command-line arguments. The playbook needs to define a clear, immediate containment step upon detecting a suspicious PowerShell command. Which action is the most effective and appropriate first containment step?
Show answer & explanation
Correct answer: B
Isolating the host is the most effective immediate containment step. It instantly severs the endpoint's network connections (except to the management console), preventing lateral movement, C2 communication, and further damage while allowing the response team to investigate the isolated machine.
- Question 5Beginner
Fundamentals · Describe the process of performing forensics analysis of infrastructure network devices
True or False: When performing forensic analysis on a Cisco ASA firewall, the output of
show conn detailis considered volatile evidence and must be captured before the device is powered down or the connection is terminated.Show answer & explanation
Correct answer: A
The statement is true. The connection table on a Cisco ASA, displayed by
show conn, contains the state of active network connections. This information is stored in RAM and is highly volatile. It will be lost upon reboot, power loss, or if the connections time out. It is a critical piece of evidence that must be collected early in an investigation. - Question 6Intermediate
Forensics Processes · Interpret binaries using objdump and other CLI tools
An investigator is analyzing a malicious binary using
objdump. The goal is to identify all the external library functions the binary calls, such assocketorCreateProcessA, to understand its capabilities. Whichobjdumpflag should be used to display this information?objdump ______ malware.exeShow answer & explanation
Correct answer: C
The
-Tor--dynamic-symsflag specifically displays the dynamic symbol table entries. For an executable, this includes the list of functions it imports from shared libraries (DLLs on Windows, .so files on Linux), which is exactly what the investigator needs. - Question 7Advanced
Incident Response Techniques · Recommend the Cisco security solution for detection and prevention
Case Study:
A healthcare organization suffered a security incident where patient data was exfiltrated. The incident response team has been assembled and is in the eradication phase. Analysis reveals the threat actor gained initial access via a phishing email, installed a persistent backdoor, and then used PsExec for lateral movement to a database server containing the patient records. The actor then compressed the records into a single archive and exfiltrated it over DNS tunneling to an external server.
The CISO has tasked the team with ensuring this specific attack chain cannot be repeated. The organization uses Cisco Umbrella for DNS security, Cisco Secure Endpoint for EDR, and Cisco Secure Firewall (FTD) at the perimeter. The team needs to recommend several mitigation techniques that address different stages of this attack.
Which combination of actions provides the most comprehensive defense-in-depth strategy to prevent a recurrence of this specific attack chain?
Show answer & explanation
Correct answer: B
This is the most comprehensive strategy. Blocking unauthorized outbound DNS on the firewall directly stops DNS tunneling exfiltration. The custom rule in Secure Endpoint targets the lateral movement technique (PsExec). Cisco Umbrella (already implied by the DNS rule) handles the initial phishing link. This combination addresses multiple phases of the attack chain: initial access, lateral movement, and exfiltration.
- Question 8Intermediate
Forensics Processes · Analyze logs from modern web applications and servers (Apache and NGINX)
An analyst is reviewing logs from an NGINX web server after a suspected SQL injection attack. Which of the following log entries is the strongest indicator that an attacker was attempting to perform a union-based SQL injection attack?
graph LR A[Attacker] -->|HTTP Request| B(NGINX Web Server) B -->|Query| C(Database) C -->|Results| B B -->|HTTP Response| AShow answer & explanation
Correct answer: C
This log entry is a clear indicator of a union-based SQL injection attack. The presence of the
UNION SELECTstatement is the defining characteristic, used to combine the results of the original query with results from a new query crafted by the attacker (in this case, to steal usernames and passwords). - Question 9Beginner
Forensics Techniques · Construct Python, PowerShell, and Bash scripts to parse and search logs
An incident responder uses a Bash script to quickly search through gigabytes of proxy logs for signs of a specific malware's C2 communication. The malware is known to use
.pwdomains. Which command is the most efficient for finding all log lines containing a.pwdomain and writing them to a file namedsuspicious_domains.txt?Show answer & explanation
Correct answer: B
This is the correct and most efficient command.
grepis the standard tool for searching text. The pattern"\.pw"correctly escapes the dot, ensuring it is treated as a literal character rather than a wildcard, thus preventing false positives for strings likesomepw.com. It reads the log file and redirects the output to the specified text file. - Question 10IntermediateSelect 2
Incident Response Processes · Evaluate the relevant components from the ThreatGrid report
A security analyst receives a ThreatGrid report for a suspicious executable. The report shows a threat score of 98 and lists several behavioral indicators. Which two indicators from the report would be most critical for prioritizing this alert and initiating an incident response? (Choose two.)
Show answer & explanation
Correct answers: B, C
Writing files to protected system directories like
System32is a highly suspicious activity and a strong indicator of malware attempting to install components or establish persistence. This is a critical behavioral indicator.Network communication with a known malicious entity, such as a botnet command-and-control server, is one of the most severe indicators. It confirms the malware is active and attempting to receive commands or exfiltrate data, requiring immediate incident response.
Ready for the real thing?
The full 300-215 simulator has every exam-style question, timed mode, and instant scoring.