Cisco Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity 300-215 CBRFIR Exam Questions

Page: 1 / 14
Total 184 questions
Question 1

Rotor to the exhibit.

A cybersecurity analyst must analyst the logs from an Apache server for the client. The concern is that an offboarded employee home IP address was potentially used to access the company web server via a still active VPN connection Based on this log entry, what should an analyst conclude?



Answer : D


Question 2

What are two features of Cisco Secure Endpoint? (Choose two.)



Answer : A, C

Cisco Secure Endpoint (formerly AMP for Endpoints) offers features like:

File trajectory: to track file behavior and spread across endpoints.

Orbital Advanced Search: for querying endpoint data to detect threats in real time.


Question 3

Refer to the exhibit.

What is occurring?



Answer : D

The command in the image uses schtasks /create with the ONLOGON schedule and System user context to execute test.exe. This is a well-documented persistence technique, where an attacker ensures that a malicious executable is launched automatically at each system logon. This kind of scheduled task creation aligns with persistence techniques in the MITRE ATT&CK framework (T1053).

---


Question 4

Refer to the exhibit. A security analyst uses dynamic analysis to examine an executable. Which action does the output indicate that the executable performs?

{

"category": "filesystem",

"api": "CreateFileW",

"arguments": [

{"name": "lpFileName", "value": "\\\\.\\pipe\\net\\NtControlPipe10"},

{"name": "dwDesiredAccess", "value": "GENERIC_READ | GENERIC_WRITE"}

]

}



Answer : A

The CreateFileW call opens \\.\pipe\net\NtControlPipe10 with both GENERIC_READ and GENERIC_WRITE access. The \\.\pipe\ namespace identifies a Windows named pipe, an interprocess-communication mechanism that allows processes to exchange data. The output therefore indicates process-to-process communication through a named pipe. Nothing in the artifact shows destination ports or repeated connection attempts, so it does not establish port scanning. CreateFileW is a Windows API used to open files, devices, and pipes; it is not a keylogger module. The hexadecimal value appears as an exit code associated with ExitProcess, not as a registry modification, eliminating option D. Analysts should correlate the pipe name with process ancestry and other sandbox events because malware commonly uses named pipes for coordination or command exchange. This maps to CBRFIR objective 2.3, evaluating malware-analysis output to identify host activity. Cisco CBRFIR v1.2 exam topics

================


Question 5

A threat actor has successfully attacked an organization and gained access to confidential files on a laptop. What plan should the organization initiate to contain the attack and prevent it from spreading to other network devices?



Answer : C

Once an incident has occurred, the appropriate course of action is to engage the organization's Incident Response (IR) plan. This is a structured approach to contain, analyze, and eradicate threats before they spread across the network.

The Cisco CyberOps Associate study guide emphasizes:

''Incident response and handling are essential within an organization... The main objective of implementing an incident handling process is to reduce the impact of a cyber-attack, ensure the damages caused are assessed, and implement recovery procedures''.

In particular, the containment phase of IR is focused on isolating the threat and preventing lateral movement or further compromise.

Options such as 'root cause' or 'attack surface' are relevant at later stages of analysis and mitigation, not immediate containment. Therefore, the correct answer is C.


Question 6

Refer to the exhibit.

A web hosting company analyst is analyzing the latest traffic because there was a 20% spike in server CPU usage recently. After correlating the logs, the problem seems to be related to the bad actor activities. Which attack vector is used and what mitigation can the analyst suggest?



Answer : D, D

Comprehensive and Detailed

The log entries show repeated SSH login attempts for various invalid usernames (e.g., admin, phoenix, rainbow, test, user, etc.) from different source ports. These are clear signs of a brute-force attack---an automated process trying multiple usernames and passwords in hopes of gaining access.

Mitigating such attacks includes:

Implementing account lockout policies (e.g., locking an account after several failed login attempts).

Enabling Multi-Factor Authentication (MFA) to ensure that password guessing alone is insufficient for account access.

Therefore, the correct answer is:


Question 7

Refer to the exhibit.

import requests

def check_status(url):

response = requests.get(url)

return response.status_code

In which programming language is the code written, and what is it trying to accomplish?



Answer : D

The syntax identifies Python: it uses import, defines a function with def, terminates the function header with a colon, and relies on indentation rather than braces. The requests library sends an HTTP GET request to the supplied URL, and response.status_code returns the server's HTTP result code. Repeated execution can test whether a website responds successfully, which makes ''website-uptime monitor'' the closest description among the choices. Strictly, this short function performs one availability check; a production monitor would add scheduling, timeouts, exception handling, expected-status logic, logging, and alerting. It neither parses a dataset nor implements a content-management system, and it does not write response content to a file. Option D is therefore correct. This is within CBRFIR objectives 2.4 and 2.5. The official Requests quick-start documentation demonstrates requests.get() and status_code in this exact role.


Page:    1 / 14   
Total 184 questions