Cisco 300-220 - Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity Exam
Page: 3 / 12
Total 60 questions
Question #11 (Topic: Topic 2, Threat Modeling Techniques
)
Refer to the exhibit.

The Security Operations team is reviewing firewall logs and decrypts this HTTP request coming one of finance team member’s endpoints.
Which stage of the Cyber Kill Chain does the evidence point to?

The Security Operations team is reviewing firewall logs and decrypts this HTTP request coming one of finance team member’s endpoints.
Which stage of the Cyber Kill Chain does the evidence point to?
A. Command and Control: establishing persistent C2 channels
B. Installation: installing malware on endpoints
C. Exfiltration: transferring data to remote server
D. Delivery: transmitting malicious payload to target
Answer: C
Question #12 (Topic: Topic 2, Threat Modeling Techniques
)
A task has been assigned to enhance defenses against APT actors within a mid-sized technology company. Attacks by the adversaries are sophisticated and prolonged, and they use various tactics to infiltrate and persist within target networks. The company is focusing on the tactics used by the adversaries to significantly improve overall security posture. A review of the Pyramid of Pain model has been conducted, highlighting different levels of threat indicators, from simple hash values to complex TTPs. The objective is to enhance detection capabilities.
Which approach should be taken to detect APT activity at the Tactics level of the Pyramid of Pain?
Which approach should be taken to detect APT activity at the Tactics level of the Pyramid of Pain?
A. monitoring all available network logs for specific IPs linked to known APT activities
B. blocking newly registered domains that have not been accessed before by company personnel
C. analyzing logs to identify patterns of behavior matching APT tactics from MITRE ATT&CK
D. using hash values to identify known malware files used in previous APT campaigns
Answer: C
Question #13 (Topic: Topic 2, Threat Modeling Techniques
)
Refer to the exhibit.

A forensic team must investigate how the company website was defaced. The team isolates the web server, clones the disk, and analyzes the logs.
Which technique was used by the attacker initially to access the website?

A forensic team must investigate how the company website was defaced. The team isolates the web server, clones the disk, and analyzes the logs.
Which technique was used by the attacker initially to access the website?
A. drive-by compromise
B. external remote services
C. exploit public-facing application
D. command and scripting interpreter
Answer: C
Question #14 (Topic: Topic 2, Threat Modeling Techniques
)
A hacking group targets a construction company by sending emails that contain a malicious macro. An employee at the company executes the macro, and a PowerShell command is executed that downloads a file with further instructions from a website. The malware installs a keylogger on the employee’s computer and reports keystrokes to a C2 server.
What is being used according to the MITRE ATT&CK framework?
What is being used according to the MITRE ATT&CK framework?
A. ingress tool transfer
B. fallback channels
C. drive-by compromise
D. indirect command execution
Answer: A
Question #15 (Topic: Topic 3, Threat Actor Attribution Techniques
)
A threat hunting team tries to classify the IoT malware families based on abnormal patterns of activities.
Which method for IoT malware family classification is described?
Which method for IoT malware family classification is described?
A. random forest
B. decision tree learning
C. random number generator
D. gradient boosting
Answer: B