A security analyst notices unusual connections while monitoring traffic. What is the attack vector,
and which action should be taken to prevent this type of event?Free 300-215 Practice Test Questions and Answers (2026)
Q: 1
Refer to the exhibit.
A security analyst notices unusual connections while monitoring traffic. What is the attack vector,
and which action should be taken to prevent this type of event?
A security analyst notices unusual connections while monitoring traffic. What is the attack vector,
and which action should be taken to prevent this type of event?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A security team is notified from a Cisco ESA solution that an employee received an advertising email
with an attached .pdf extension file. The employee opened the attachment, which appeared to be an
empty document. The security analyst cannot identify clear signs of compromise but reviews running
processes and determines that PowerShell.exe was spawned by CMD.exe with a grandparent
AcroRd32.exe process. Which two actions should be taken to resolve this issue? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
An engineer received a report of a suspicious email from an employee. The employee had already
opened the attachment, which was an empty Word document. The engineer cannot identify any
clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was
spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the
engineer should take?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A security team is discussing lessons learned and suggesting process changes after a security breach
incident. During the incident, members of the security team failed to report the abnormal system
activity due to a high project workload. Additionally, when the incident was identified, the response
took six hours due to management being unavailable to provide the approvals needed. Which two
steps will prevent these issues from occurring in the future? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
An employee receives an email from a “trusted” person containing a hyperlink that is malvertising.
The employee clicks the link and the malware downloads. An information analyst observes an alert
at the SIEM and engages the cybersecurity team to conduct an analysis of this incident in accordance
with the incident response plan. Which event detail should be included in this root cause analysis?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
What is the steganography anti-forensics technique?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
An “unknown error code” is appearing on an ESXi host during authentication. An engineer checks the
authentication logs but is unable to identify the issue. Analysis of the vCenter agent logs shows no
connectivity errors. What is the next log file the engineer should check to continue troubleshooting
this error?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Refer to the exhibit.
An engineer is analyzing a .LNK (shortcut) file recently received as an email attachment and blocked
by email security as suspicious. What is the next step an engineer should take?
An engineer is analyzing a .LNK (shortcut) file recently received as an email attachment and blocked
by email security as suspicious. What is the next step an engineer should take?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Refer to the exhibit.
A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the
initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the
Wireshark traffic logs?
A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the
initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the
Wireshark traffic logs?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Refer to the exhibit.
According to the Wireshark output, what are two indicators of compromise for detecting an Emotet
malware download? (Choose two.)
According to the Wireshark output, what are two indicators of compromise for detecting an Emotet
malware download? (Choose two.)Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
Refer to the exhibit.
What is the IOC threat and URL in this STIX JSON snippet?
What is the IOC threat and URL in this STIX JSON snippet?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
In a secure government communication network, an automated alert indicates the presence of
anomalous DLL files injected into the system memory during a routine update of communication
protocols. These DLL files are exhibiting beaconing behavior to a satellite IP known for signal
interception risks. Concurrently, there is an uptick in encrypted traffic volumes that suggests possible
data exfiltration. Which set of actions should the security engineer prioritize?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Refer to the exhibit.


Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Refer to the exhibit.
A security analyst is reviewing alerts from the SIEM system that was just implemented and notices a
possible indication of an attack because the SSHD system just went live and there should be nobody
using it. Which action should the analyst take to respond to the alert?
A security analyst is reviewing alerts from the SIEM system that was just implemented and notices a
possible indication of an attack because the SSHD system just went live and there should be nobody
using it. Which action should the analyst take to respond to the alert?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an
external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file’s
behavior. Which logs should be reviewed next to evaluate this file further?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
An insider scattered multiple USB flash drives with zero-day malware in a company HQ building.
Many employees connected the USB flash drives to their workstations. An attacker was able to get
access to endpoints from outside, steal user credentials, and exfiltrate confidential information from
internal web resources. Which two steps prevent these types of security incidents in the future?
(Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Refer to the exhibit.
What should be determined from this Apache log?
What should be determined from this Apache log?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Over the last year, an organization’s HR department has accessed data from its legal department on
the last day of each month to create a monthly activity report. An engineer is analyzing suspicious
activity alerted by a threat intelligence platform that an authorized user in the HR department has
accessed legal data daily for the last week. The engineer pulled the network data from the legal
department’s shared folders and discovered above average-size data dumps. Which threat actor is
implied from these artifacts?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Refer to the exhibit.
An engineer is analyzing a TCP stream in Wireshark after a suspicious email with a URL. What should
be determined about the SMB traffic from this stream?
An engineer is analyzing a TCP stream in Wireshark after a suspicious email with a URL. What should
be determined about the SMB traffic from this stream?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
A cybersecurity analyst is examining a complex dataset of threat intelligence information from
various sources. Among the data, they notice multiple instances of domain name resolution requests
to suspicious domains known for hosting C2 servers. Simultaneously, the intrusion detection system
logs indicate a series of network anomalies, including unusual port scans and attempts to exploit
known vulnerabilities. The internal logs also reveal a sudden increase in outbound network traffic
from a specific internal host to an external IP address located in a high-risk region. Which action
should be prioritized by the organization?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20