Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco Certified Specialist - Threat Hunting and Defending 300-220 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 300-220 Premium Access

View all detail and faqs for the 300-220 exam


560 Students Passed

85% Average Score

90% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

According to the MITRE ATT&CK framework, how is the password spraying technique classified?

Options:

A.

Privilege escalation

B.

Initial access

C.

Lateral movement

D.

Credential access

Questions # 12:

A SOC team must prepare for a new phishing campaign that tricks users into clicking a malicious URL to download a file. When the file executes, it creates a Windows process that harvests user credentials. The team must configure the SIEM tool to receive an alert if a suspicious process is detected. Which two rules must the team create in the SIEM tool? (Choose two.)

Options:

A.

Rule that detects processes created by the users

B.

Rule that detects processes in nonstandard file paths

C.

Rule that detects common processes that have modified names

D.

Rule that detects changes in process ownership

E.

Rule that detects changes in process startup time

Questions # 13:

A security team is performing threat modeling for a hybrid environment consisting of on-prem Active Directory and Azure AD. The team wants to identify how an attacker could move from a compromised cloud identity to full on-prem domain dominance. Which modeling focus is MOST appropriate?

Options:

A.

Enumerating CVEs affecting domain controllers

B.

Mapping trust relationships between identity systems

C.

Assigning CVSS scores to authentication mechanisms

D.

Conducting packet-level network flow analysis

Questions # 14:

A security team wants to create a plan to protect companies from lateral movement attacks. The team already implemented detection alerts for pass-the-hash and pass-the-ticket techniques. Which two components must be monitored to hunt for lateral movement attacks on endpoints? (Choose two.)

Options:

A.

Use of the runas command

B.

Linux file systems for files that have the setuid/setgid bit set

C.

Use of Windows Remote Management

D.

Creation of scheduled task events

E.

Use of tools and commands to connect to remote shares

Questions # 15:

After completing a threat hunt that uncovered previously undetected credential abuse, the SOC wants to ensure long-term improvement in detection and response capabilities. Which action BEST represents the final and most critical phase of the threat hunting lifecycle?

Options:

A.

Immediately blocking all related IP addresses

B.

Documenting findings and updating detection logic

C.

Resetting affected user credentials

D.

Conducting additional unstructured hunts

Questions # 16:

A SOC team using Cisco security technologies wants to distinguishIndicators of Attack (IOAs)fromIndicators of Compromise (IOCs)during threat hunting. Which scenario BEST represents an IOA rather than an IOC?

Options:

A.

Detection of a known malicious file hash on an endpoint

B.

Identification of a domain listed in a threat intelligence feed

C.

Observation of repeated failed logins followed by a successful login from a new location

D.

Blocking an IP address associated with previous malware campaigns

Questions # 17:

What is the classification of the pass-the-hash technique according to the MITRE ATT&CK framework?

Options:

A.

Lateral movement

B.

Persistence

C.

Credential access

D.

Privilege escalation

Questions # 18:

A SOC leadership team wants to demonstrate the business value of investing in Cisco-based threat hunting capabilities. Which outcome BEST demonstrates that value?

Options:

A.

Increase in alerts generated by security tools

B.

Reduction in false positives across the SOC

C.

Earlier detection of attacks before data exfiltration

D.

Growth in threat intelligence subscriptions

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.