300-215
Conducting Forensic Analysis and Incident Response Using
Cisco Technologies for Cybersecurity
Up to Date products, reliable and verified.
Questions and Answers in PDF Format.
For More Information – Visit link below:
Web: www.examkill.com/
Version product
Visit us at: https://examkill.com/300-215
, Latest Version: 9.4
Question: 1
A security team is discussing lessons learned and suggesting process changes after a security
breach incident. During the incident, members of the security team failed to report the
abnormal system activity due to a high project workload. Additionally, when the incident was
identified, the response took six hours due to management being unavailable to provide the
approvals needed. Which two steps will prevent these issues from occurring in the future?
(Choose two.)
A. Introduce a priority rating for incident response workloads.
B. Provide phishing awareness training for the full security team.
C. Conduct a risk audit of the incident response workflow.
D. Create an executive team delegation plan.
E. Automate security alert timeframes with escalation triggers.
Answer: A, D
Explanation:
According to the CyberOps Technologies (CBRFIR) 300-215 study guide, during the post-incident
activity phase, it is critical to analyze lessons learned and update processes to ensure quicker
and more efficient response in the future. Specifically:
Introducing a priority rating for incident response workloads (A) helps address the issue of team
members being occupied with other tasks and unable to prioritize abnormal system activity. This
ensures incidents are handled based on severity, not just workload.
Creating an executive team delegation plan (D) addresses the issue of delays due to
unavailability of management for approvals. It ensures alternative decision-makers are available
for swift action.
These strategies are based on the NIST SP 800-61 Rev. 2 recommendations and are highlighted
in the Cisco guide’s post-incident activity phase (page 418), which emphasizes lessons learned
and how to reduce detection and response times for future incidents.
Question: 2
An engineer is investigating a ticket from the accounting department in which a user discovered
an unexpected application on their workstation. Several alerts are seen from the intrusion
detection system of unknown outgoing internet traffic from this workstation. The engineer also
notices a degraded processing capability, which complicates the analysis process. Which two
actions should the engineer take? (Choose two.)
Visit us at: https://examkill.com/300-215