Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 7 Question 42 Discussion

A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file's behavior. Which logs should be reviewed next to evaluate this file further?
B) DNS server
A) email security appliance
C) Antivirus solution
D) network device

Cisco 300-215 Exam - Topic 7 Question 42 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 42
Topic #: 7
[All 300-215 Questions]

A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file's behavior. Which logs should be reviewed next to evaluate this file further?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Venita
10 months ago
Wait, are we sure the file is actually malware? Could be a false positive, right?
upvoted 0 times
...
Robt
10 months ago
I agree, DNS logs are key! They can reveal a lot about suspicious activity.
upvoted 0 times
...
Jacinta
10 months ago
Not so sure about the email security appliance being useful here. Seems unrelated.
upvoted 0 times
...
Alesia
11 months ago
I think the antivirus solution is a good next step too. It might have more details on the file.
upvoted 0 times
...
Carolann
11 months ago
Definitely check the DNS server logs. They can show where the file is trying to connect.
upvoted 0 times
...
Pamella
11 months ago
I feel like the email security appliance might not be relevant since this is about an endpoint file, but I could be wrong.
upvoted 0 times
...
Tamesha
11 months ago
I practiced a similar question where we had to look at network device logs. That might be worth considering here too.
upvoted 0 times
...
Krystal
11 months ago
I'm not entirely sure, but I remember something about checking the antivirus solution logs for more details on the malware.
upvoted 0 times
...
Van
11 months ago
I think reviewing the DNS server logs could be really helpful since the file is trying to connect to an external site.
upvoted 0 times
...
Louisa
11 months ago
Hmm, I'm a bit unsure about this one. Is it content-based routing or filtering? I'll have to think it through carefully.
upvoted 0 times
...
Rolande
11 months ago
Okay, I think I've got this. The question is asking about the OMB memorandum that outlines the principles and decision criteria for including and funding security as part of agency IT systems. Based on that, I'm going to go with option B, OMB M-99-18.
upvoted 0 times
...
Ernestine
11 months ago
This seems like a straightforward question about the security benefits of a single sign-on policy. I'll focus on highlighting the key points like centralized access control, reduced password complexity, and improved logging.
upvoted 0 times
...
Javier
11 months ago
This seems pretty straightforward. The client wants to run the trial balance by main account, department, and division, so I'm going to go with Option B. Financial dimensions should do the trick.
upvoted 0 times
...

Save Cancel