Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 6 Question 118 Discussion

A threat hunter must analyze the threat intelligence report on APT29 and identify whether the threat actor is on the Windows machines of the customer network. According to the report the user executes a malicious file on the victim machine that establishes a C? connection over port 53 Afterward, the attacker uses a CI.I to stage and exfiltrate business data. Which two types of logs enable the threat hunter to accomplish the task? (Choose two.)
B) PowerShell togs and E) DNS logs
A) file integrity monitoring logs
C) web application firewall logs
D) NetFlow logs

Cisco 300-215 Exam - Topic 6 Question 118 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 118
Topic #: 6
[All 300-215 Questions]

A threat hunter must analyze the threat intelligence report on APT29 and identify whether the threat actor is on the Windows machines of the customer network. According to the report the user executes a malicious file on the victim machine that establishes a C? connection over port 53 Afterward, the attacker uses a CI.I to stage and exfiltrate business data. Which two types of logs enable the threat hunter to accomplish the task? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, E

Contribute your Thoughts:

0/2000 characters
Adelina
4 days ago
Definitely going with E) DNS logs. That's key for tracking that C2 connection.
upvoted 0 times
...
Simona
9 days ago
I feel like file integrity monitoring logs might not be the best choice here since the focus is on network activity rather than file changes.
upvoted 0 times
...
Margart
14 days ago
I’m a bit confused about the PowerShell logs. I know they can show script execution, but would they really help in this scenario?
upvoted 0 times
...
Nguyet
19 days ago
I remember practicing a similar question where we had to identify logs for network traffic analysis. NetFlow logs might be relevant too, right?
upvoted 0 times
...
Evangelina
24 days ago
I think DNS logs could be crucial here since the connection is over port 53, but I'm not sure about the second log type.
upvoted 0 times
...

Save Cancel