Skip to content

300-215 Practice Questions

Prepare for 300-215 with more than an answer.

232 questions in the full set20 sample questionsUpdated Aug 20, 2026
Exam fee
$300 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 5
  1. Fundamentals20%
  2. Forensics Techniques20%
  3. Incident Response Techniques30%
  4. Forensics Processes15%
  5. Incident Response Processes15%
  1. 1

    An incident responder uses a Bash script to quickly search through gigabytes of proxy logs for signs of a specific malware's C2 communication. The malware is known to use .pw domains. Which command is the most efficient for finding all log lines containing a .pw domain and writing them to a file named suspicious_domains.txt?

    Show answer details

    Correct answer: B

    This is the correct and most efficient command. grep is the standard tool for searching text. The pattern "\.pw" correctly escapes the dot, ensuring it is treated as a literal character rather than a wildcard, thus preventing false positives for strings like somepw.com. It reads the log file and redirects the output to the specified text file.

  2. 2

    A security analyst receives a ThreatGrid report for a suspicious executable. The report shows a threat score of 98 and lists several behavioral indicators. Which two indicators from the report would be most critical for prioritizing this alert and initiating an incident response? (Choose two.)

    Show answer details

    Correct answer: B, C

    Writing files to protected system directories like System32 is a highly suspicious activity and a strong indicator of malware attempting to install components or establish persistence. This is a critical behavioral indicator.

    Network communication with a known malicious entity, such as a botnet command-and-control server, is one of the most severe indicators. It confirms the malware is active and attempting to receive commands or exfiltrate data, requiring immediate incident response.

  3. 3

    When gathering evidence from cloud environments like AWS or Azure, the 'shared responsibility model' introduces unique forensic challenges. What is the primary forensic issue related to the infrastructure-as-a-service (IaaS) layer in a public cloud?

    Show answer details

    Correct answer: B

    The core challenge in IaaS forensics is the lack of physical access. Investigators cannot seize a physical server or directly access the hypervisor layer, which is managed by the cloud provider. This prevents traditional forensic techniques like cold-boot attacks or direct memory acquisition from the host machine, forcing reliance on provider APIs and logs.

  4. 4

    An analyst is investigating fileless malware that uses WMI (Windows Management Instrumentation) for persistence. Which specific location within the WMI repository should the analyst examine to find the malicious event filter, consumer, and binding that constitute the persistence mechanism?

    Show answer details

    Correct answer: B

    The CIM (Common Information Model) repository is the database that stores WMI objects, including classes and instances. Malicious persistence mechanisms created via WMI event subscriptions are stored as instances of the __EventFilter, __EventConsumer (e.g., ActiveScriptEventConsumer), and __FilterToConsumerBinding classes within this database. Analyzing the OBJECTS.DATA file in this directory is essential for this investigation.

  5. 5

    A SOC uses a SOAR platform to automate responses to common alerts. An alert for 'Potential Brute-Force Login' on a VPN gateway is triggered. Based on the following diagram, what is the most logical automated next step for the SOAR playbook to perform after the initial alert trigger?

    sequenceDiagram participant SIEM participant SOAR participant ThreatIntel as Threat Intel Platform participant Firewall SIEM->>SOAR: New Alert: Brute-Force Detected (Source IP: 203.0.113.55) SOAR-->>ThreatIntel: Enrich IP: 203.0.113.55 ThreatIntel-->>SOAR: Response: IP is Malicious (Confidence: 95%) SOAR->>Firewall: ???

    Show answer details

    Correct answer: C

    The SOAR platform has received high-confidence intelligence that the source IP is malicious. The most logical, automated, and effective response is to immediately block this IP at the network perimeter (the firewall) to stop the brute-force attack and prevent any further malicious activity from that source.

  6. 6

    Which antiforensic technique involves modifying the file signature (magic numbers) in a file's header to make it appear as a different file type, such as changing a .exe file's header to match a .jpg?

    Show answer details

    Correct answer: B

    Transmogrification is the specific term for altering a file's header or magic numbers to disguise its actual file type. This technique attempts to trick automated analysis tools and forensic investigators who rely on file signatures for initial identification.

  7. 7

    True or False: Using the strings command on a binary and piping the output to grep for a specific keyword is considered a form of dynamic malware analysis.

    Show answer details

    Correct answer: B

    The statement is false. Examining a file without executing it is the definition of static analysis. The strings command reads the binary file from disk to extract printable character sequences. This does not involve running the code, so it is a form of static, not dynamic, analysis.

  8. 8

    A SOC analyst at an e-commerce company receives a high-severity alert from their Cisco Secure Firewall. The alert indicates a successful SQL injection attack against a public-facing web server, originating from an IP address in a foreign country. The application team has confirmed they cannot patch the vulnerability for at least 24 hours. Which mitigation technique should the analyst recommend as the most immediate and effective measure?

    Show answer details

    Correct answer: C

    Deploying a virtual patch on the IPS is the best immediate action. This technique uses the IPS to inspect traffic and block the specific malicious pattern (the SQL injection attempt) before it reaches the vulnerable server. This mitigates the risk without taking the server offline (which causes business impact) or only blocking a single source IP (which the attacker can easily change). Shutting down the database is a last resort and highly disruptive.

  9. 9

    A security team receives an alert from Cisco Secure Cloud Analytics (Stealthwatch Cloud) for an AWS EC2 instance. The alert, 'Anomalous RDP Brute Force,' indicates the instance is receiving an unusually high number of inbound RDP connection attempts from multiple external IP addresses. Which TWO actions are appropriate mitigation steps? (Select TWO)

    graph TD subgraph Internet Attacker1 Attacker2 Attacker3 end subgraph AWS_VPC SG[Security Group] EC2[EC2 Instance] end Attacker1 -->|RDP Port 3389| SG Attacker2 -->|RDP Port 3389| SG Attacker3 -->|RDP Port 3389| SG SG -->> EC2

    Show answer details

    Correct answer: A, C

    The most effective way to stop a brute-force attack against a cloud instance is to restrict network access. Modifying the Security Group to allow RDP traffic only from known, trusted IP addresses immediately cuts off the attackers. Additionally, for administrative access, using a bastion host or AWS Systems Manager provides a more secure, audited, and controlled access method than exposing RDP directly to the internet.

    The most effective way to stop a brute-force attack against a cloud instance is to restrict network access. Modifying the Security Group to allow RDP traffic only from known, trusted IP addresses immediately cuts off the attackers. Additionally, for administrative access, using a bastion host or AWS Systems Manager provides a more secure, audited, and controlled access method than exposing RDP directly to the internet.

  10. 10

    A SOC has received a high-fidelity alert from Cisco Secure Endpoint indicating that a process, svchost.exe, has initiated a network connection to a known malicious IP address. The endpoint is a critical database server. Using a SOAR platform integrated with the Cisco security suite, what is the most appropriate and immediate automated mitigation action to recommend?

    Show answer details

    Correct answer: C

    The most critical and immediate action for a confirmed high-fidelity alert on a critical server is containment. Using a SOAR playbook to trigger Cisco Secure Endpoint's host isolation feature is the fastest and most effective way to prevent lateral movement or further malicious activity from the compromised host. While blocking the IP is a good step, it doesn't stop the malware on the host from attempting to communicate with other internal systems. A vulnerability scan is too slow and does not address the active threat.

Create an account to continue.