Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity v1.0

Page:    1 / 4   
Exam contains 60 questions

Refer to the exhibit.

A security analyst at a company performs a forensic analysis of an endpoint after the endpoint is marked as infected by an endpoint detection and response solution. After further investigation, the analyst discovers that a registry value was modified.
According to the MITRE ATT&CK framework, which technique did the malware use?

  • A. resource development
  • B. initial access
  • C. defense evasion
  • D. execution


Answer : C

Refer to the exhibit.

A code analysis is performed by using the Semgrep tool. The tool reports that a security issue occurred during the connection to the database.
Which security vulnerability is flagged by the tool?

  • A. denial of service attack
  • B. unauthorized login
  • C. privilege escalation
  • D. SQL injection


Answer : D

A security analyst suspects that the latest attack on one of company machines is of the memory resident kind, given the telemetry observed so far.
Which step must the analyst take next to confirm this suspicion?

  • A. Reboot the server to clear any malicious processes from memory and then run a comprehensive malware scan.
  • B. Analyze network traffic logs for any suspicious activity and perform packet capture to decrypt unknown communication.
  • C. Perform a full disk scan using antivirus software to identify and install an EDR product to observe how the system behaves.
  • D. Capture a memory dump of the affected system and analyze it using forensic tools to identify malicious processes.


Answer : D

A security engineer notices a user locked out of an email account after multiple failed sign-ins. Upon further investigation, it appears other users experienced the same issue. The lockout was caused by using incorrect credentials during authentication.
What is the indicator of the attack?

  • A. password resets by multiple email accounts
  • B. change in lockout policy by an administrator
  • C. sign-in from different devices on the same IP address
  • D. short burst of sign-in attempts from different countries


Answer : D

Refer to the exhibit.

The SOC lead received the scope of a penetration test conducted against the company's assets within the last 4 hours. Documentation does not seem to contain any authorized IP address range and the testing company must perform only a surface-level scan and database probing. As the SOC analysts review server logs to determine whether recent activities indicate an authorized penetration test or a possible attack, a few suspicious entries are discovered by the team.
Which two log entries points to a possibly successful unauthorized attack? (Choose two.)

  • A. instance of “Haxxilla/5.0” user agent
  • B. event with SQLDestroyer/6.0 user agent
  • C. user agent “M Delta Security Services”
  • D. presence of “NetworkScanner/3.0” user agent
  • E. occurrence of SQLMap user agent


Answer : AB

A SOC team must prepare for a new phishing campaign that tricks users into clicking a malicious URL to download a file. When the file executes, it creates a Windows process that harvests user credentials. The team must configure the SIEM tool to receive an alert if a suspicious process is detected.
Which two rules must the team create in the SIEM tool? (Choose two.)

  • A. rule that detects processes created by the users
  • B. rule that detects changes in process ownership
  • C. rule that detects common processes that have modified names
  • D. rule that detects processes in nonstandard file paths
  • E. rule that detects changes in process startup time


Answer : CD

Refer to the exhibit.

Which technique is used by the attacker?

  • A. Use a base64-encoded VBScript that is decoded and executed on the endpoint.
  • B. Scan using a batch file created on the fly that contains the command.
  • C. Set up persistence by creating a shortcut for the malicious macro in the user’s Startup directory.
  • D. Perform a preliminary check to verify if the victim has already been compromised.


Answer : A

A security team receives a notification about uncommon and blocked web traffic. The team begins to investigate the proxy logs and discovers traffic from infrequently used user agents to domains that are categorized as malware.
What are two additional proxy log threat indicators? (Choose two.)

  • A. antivirus alerts about executable files
  • B. multiple outbound connections to TCP port 443 on the firewall
  • C. URLs that have a direct IP address in place
  • D. HTTP methods, such as POST and PUT, that exfiltrate data to external cloud storage
  • E. uncommon sign-in from an external, first seen IP address combined with high amounts of blocked traffic


Answer : CD

The security team detects an alert regarding a potentially malicious file name Financial_Data_123456789.pdf downloaded by a user. Upon reviewing SIEM logs and Cisco secure endpoint the team confirms that the file was obtained from an untrusted website. The hash analysis of the file returns an unknown status.
Which action must be done next?

  • A. Investigate the reputation of the untrusted website.
  • B. Review the directory path where the file is stored.
  • C. Run a complete malware scan on the user’s workstation.
  • D. Submit the file for sandboxing.


Answer : D

The SOC team receives threat intelligence about a new ransomware variant spreading across businesses. After validating existing use cases regarding suspicious emails, a new use case is created based on known indicators of compromise related to the specific ransomware variant. The emphasis is on flagging the ransomware attack during the execution phase.
What should be monitored?

  • A. sudden increase in outbound traffic
  • B. changes in My Documents file directory
  • C. large numbers of file modifications
  • D. suspicious DNS requests with no replies


Answer : C

Refer to the exhibit.

The cybersecurity team at a company detects an ongoing attack directed at the web server that hosts the company website. The team analyzes the logs of the web application firewall and discovers several HTTP requests encoded in Base64. The team decodes the payloads and retrieves the HTTP requests.
What did the attackers use to exploit the server?

  • A. unicode encoding
  • B. cross-site scripting (XSS)
  • C. directory traversal
  • D. SQL injection


Answer : D

Refer to the exhibit.

A security engineer notices that a Windows Batch script includes calls to suspicious APIs.
How will the script affect the system when it is executed?

  • A. The internet connection is disabled.
  • B. The host is put in sleep mode.
  • C. The host version is retrieved.
  • D. Files are encrypted.


Answer : D

Refer to the exhibit.

The security team examines a Windows host after receiving an alert that the host authenticated over the network to another host by using a local admin account. The team discovers a process creation event in the sysmon logs of the host.
Which action did the host perform?

  • A. rootkit installation
  • B. network host discovery
  • C. lateral movement
  • D. vertical privilege escalation


Answer : C

Refer to the exhibit.

A penetration test performed against a web application generates the error message.
Which two pieces of information are exposed? (Choose two.)

  • A. service and version of the web server
  • B. Apache Jasper is vulnerable to path injection.
  • C. version of the web browser
  • D. technology used by the application
  • E. internal paths of the web server


Answer : AD

Refer to the exhibit.

Which level of the Pyramid of Pain and phase of the Threat Hunting Maturity Model is being used?

  • A. Challenging, HM3
  • B. Hashes, HM2
  • C. Simple, HM1
  • D. TTPs, HM1


Answer : C

Page:    1 / 4   
Exam contains 60 questions

Talk to us!


Have any questions or issues ? Please dont hesitate to contact us

Certlibrary.com is owned by MBS Tech Limited: Room 1905 Nam Wo Hong Building, 148 Wing Lok Street, Sheung Wan, Hong Kong. Company registration number: 2310926
Certlibrary doesn't offer Real Microsoft Exam Questions. Certlibrary Materials do not contain actual questions and answers from Cisco's Certification Exams.
CFA Institute does not endorse, promote or warrant the accuracy or quality of Certlibrary. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.
Terms & Conditions | Privacy Policy | Amazon Exams | Cisco Exams | CompTIA Exams | Databricks Exams | Fortinet Exams | Google Exams | Microsoft Exams | VMware Exams