Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 2 Question 11 Discussion

A security team is performing threat modeling for a hybrid environment consisting of on-prem Active Directory and Azure AD. The team wants to identify how an attacker could move from a compromised cloud identity to full on-prem domain dominance. Which modeling focus is MOST appropriate?
B) Mapping trust relationships between identity systems
A) Enumerating CVEs affecting domain controllers
C) Assigning CVSS scores to authentication mechanisms
D) Conducting packet-level network flow analysis

Cisco 300-220 Exam - Topic 2 Question 11 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 11
Topic #: 2
[All 300-220 Questions]

A security team is performing threat modeling for a hybrid environment consisting of on-prem Active Directory and Azure AD. The team wants to identify how an attacker could move from a compromised cloud identity to full on-prem domain dominance. Which modeling focus is MOST appropriate?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is mapping trust relationships between identity systems. Hybrid identity environments introduce complex trust boundaries that attackers routinely exploit.

Modern breaches increasingly involve identity pivoting, where attackers compromise a cloud identity and abuse synchronization, federation, or conditional access misconfigurations to escalate into on-prem Active Directory. These attack paths often do not rely on software vulnerabilities at all.

Option A is too narrow and focuses only on technical exploits. Option C measures severity but does not model movement. Option D analyzes traffic but does not explain privilege escalation pathways.

By mapping trust relationships---such as Azure AD Connect synchronization, service principals, hybrid admin roles, and conditional access exclusions---defenders can identify chained attack paths that enable privilege escalation without exploiting code.

From a threat hunting standpoint, this modeling enables:

Hypothesis-driven hunts

Detection of abnormal role assumptions

Visibility into identity abuse

This approach aligns with attack path modeling, a critical evolution of traditional threat modeling for identity-centric environments. Therefore, option B is correct.


Contribute your Thoughts:

0/2000 characters
Kaitlyn
13 days ago
A could be relevant, but it’s not the main focus here.
upvoted 0 times
...
Rasheeda
18 days ago
Agreed! Understanding how identities interact is crucial.
upvoted 0 times
...
Ashley
24 days ago
I think B is the best choice. Trust relationships are key.
upvoted 0 times
...
Chana
29 days ago
Surprised no one mentioned CVSS scores, they matter too!
upvoted 0 times
...
Jonelle
1 month ago
Totally agree with B, it’s all about the trust!
upvoted 0 times
...
Darci
1 month ago
Wait, why not D? Packet analysis can reveal a lot!
upvoted 0 times
...
Rodolfo
1 month ago
I think A could be useful too, but not the main focus.
upvoted 0 times
...
Alethea
2 months ago
B is definitely the way to go! Trust relationships are key.
upvoted 0 times
...
Coletta
2 months ago
Packet-level analysis seems a bit too technical for this scenario. I feel like understanding the trust relationships is more relevant to the attack vector described.
upvoted 0 times
...
Francoise
2 months ago
I think we practiced a similar question where trust relationships were highlighted as a key factor in lateral movement. That makes me lean towards option B.
upvoted 0 times
...
Jacquelyne
2 months ago
I'm not entirely sure, but I feel like enumerating CVEs could be useful too, especially if we're looking at vulnerabilities in domain controllers.
upvoted 0 times
...
Craig
2 months ago
I remember we discussed how trust relationships are crucial in hybrid environments, so I think mapping those might be the right focus here.
upvoted 0 times
...

Save Cancel