Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity (CBRFIR) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 232 questions. Use the simulator for timed and flashcard mode.

Try Simulator

300-215 Sample Questions

  1. Question 1

    Q1

    A SOC analyst at an e-commerce company receives a high-severity alert from their Cisco Secure Firewall. The alert indicates a successful SQL injection attack against a public-facing web server, originating from an IP address in a foreign country. The application team has confirmed they cannot patch the vulnerability for at least 24 hours. Which mitigation technique should the analyst recommend as the most immediate and effective measure?

    Show answer & explanation

    Correct answer: C

    Deploying a virtual patch on the IPS is the best immediate action. This technique uses the IPS to inspect traffic and block the specific malicious pattern (the SQL injection attempt) before it reaches the vulnerable server. This mitigates the risk without taking the server offline (which causes business impact) or only blocking a single source IP (which the attacker can easily change). Shutting down the database is a last resort and highly disruptive.

  2. Question 2

    Q2Multiple answers

    A security team receives an alert from Cisco Secure Cloud Analytics (Stealthwatch Cloud) for an AWS EC2 instance. The alert, 'Anomalous RDP Brute Force,' indicates the instance is receiving an unusually high number of inbound RDP connection attempts from multiple external IP addresses. Which TWO actions are appropriate mitigation steps? (Select TWO)

    graph TD subgraph Internet Attacker1 Attacker2 Attacker3 end subgraph AWS_VPC SG[Security Group] EC2[EC2 Instance] end Attacker1 -->|RDP Port 3389| SG Attacker2 -->|RDP Port 3389| SG Attacker3 -->|RDP Port 3389| SG SG -->> EC2

    Show answer & explanation

    Correct answers: A, C

    The most effective way to stop a brute-force attack against a cloud instance is to restrict network access. Modifying the Security Group to allow RDP traffic only from known, trusted IP addresses immediately cuts off the attackers. Additionally, for administrative access, using a bastion host or AWS Systems Manager provides a more secure, audited, and controlled access method than exposing RDP directly to the internet.

  3. Question 3

    Q3

    A SOC has received a high-fidelity alert from Cisco Secure Endpoint indicating that a process, svchost.exe, has initiated a network connection to a known malicious IP address. The endpoint is a critical database server. Using a SOAR platform integrated with the Cisco security suite, what is the most appropriate and immediate automated mitigation action to recommend?

    Show answer & explanation

    Correct answer: C

    The most critical and immediate action for a confirmed high-fidelity alert on a critical server is containment. Using a SOAR playbook to trigger Cisco Secure Endpoint's host isolation feature is the fastest and most effective way to prevent lateral movement or further malicious activity from the compromised host. While blocking the IP is a good step, it doesn't stop the malware on the host from attempting to communicate with other internal systems. A vulnerability scan is too slow and does not address the active threat.

  4. Question 4

    Q4

    A SOC uses Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) to monitor its AWS environment. An alert is generated for 'Anomalous Port Usage' from an EC2 instance that typically only communicates over TCP/443. The new traffic is a long-lived connection over TCP/6667. What is the most likely cause of this alert?

    Show answer & explanation

    Correct answer: B

    Cisco Secure Cloud Analytics excels at behavioral analysis and anomaly detection. The alert indicates a deviation from the instance's normal traffic baseline. TCP port 6667 is the standard port for Internet Relay Chat (IRC), a protocol historically and currently used by malware for command and control (C2) communications. A long-lived connection on this non-standard port from a web server is a very strong indicator of compromise.

  5. Question 5

    Q5Multiple answers

    A security team receives an alert from Cisco Secure Cloud Analytics (Stealthwatch Cloud) indicating that an EC2 instance in their AWS environment is making numerous outbound RDP connections to multiple external IP addresses. Which TWO actions should be taken to mitigate this threat and improve the security posture? (Select TWO)

    Show answer & explanation

    Correct answers: B, E

    This is a direct and immediate containment action. The observed behavior indicates the instance may be compromised and used for scanning or brute-forcing other RDP servers. Blocking outbound RDP (TCP/3389) at the network layer via the Security Group will immediately stop the malicious activity.

    This follows the principles of incident response: contain, eradicate, and recover. Isolating the instance (e.g., by moving it to a quarantined security group with no ingress/egress) preserves it for forensic analysis to determine the root cause. The long-term solution is to terminate the compromised instance and redeploy a clean one, ensuring the vulnerability that led to the compromise is fixed in the new AMI.

  6. Question 6

    Q6

    During a memory forensics investigation of a Windows system using Volatility, an analyst suspects a process hollowing attack. Which plugin should be used to compare the Process Environment Block (PEB) in-memory structure against the on-disk executable to identify this specific type of injection?

    Show answer & explanation

    Correct answer: C

    The hollowfind plugin is specifically designed to detect process hollowing techniques. It scans for discrepancies between a process's in-memory data structures (like the PEB) and its corresponding on-disk file, which is the hallmark of this attack.

  7. Question 7

    Q7

    A SOC analyst is reviewing Cisco Secure Network Analytics (Stealthwatch) alerts and notices a host exhibiting a 'Custom Security Event - High Concern Index' alarm. The host is making numerous small outbound connections to various IP addresses on non-standard ports, a pattern inconsistent with its baseline behavior. This behavior is indicative of which stage of an attack?

    Show answer & explanation

    Correct answer: B

    The pattern of numerous small, outbound connections to various IPs on non-standard ports is a classic indicator of C2 beaconing or scanning for a live C2 server. Cisco Secure Network Analytics excels at detecting such behavioral anomalies against a learned baseline of normal traffic.

  8. Question 8

    Q8Multiple answers

    An incident responder is creating a YARA rule to detect a specific malware family that uses a custom XOR encoding routine on its configuration strings. To improve the rule's resilience against minor malware variants, which two sections should be included? (Choose two.)

    Show answer & explanation

    Correct answers: B, D

    The decoding routine is often a stable piece of code across malware variants. Creating a signature based on the immutable byte patterns of this logic provides a highly resilient detection mechanism.

    A strong condition, such as (uint32(0) == 0x5A4D) and (2 of ($group1)) and (all of ($group2)), ensures that multiple pieces of evidence must be found. This significantly reduces false positives and makes the rule more reliable and resilient against simple changes.

  9. Question 9

    Q9

    A financial institution is implementing a new incident response playbook for handling fileless malware attacks that leverage PowerShell. The primary detection tool is Cisco Secure Endpoint, which logs all process command-line arguments. The playbook needs to define a clear, immediate containment step upon detecting a suspicious PowerShell command. Which action is the most effective and appropriate first containment step?

    Show answer & explanation

    Correct answer: B

    Isolating the host is the most effective immediate containment step. It instantly severs the endpoint's network connections (except to the management console), preventing lateral movement, C2 communication, and further damage while allowing the response team to investigate the isolated machine.

  10. Question 10

    Q10

    True or False: When performing forensic analysis on a Cisco ASA firewall, the output of show conn detail is considered volatile evidence and must be captured before the device is powered down or the connection is terminated.

    Show answer & explanation

    Correct answer: A

    The statement is true. The connection table on a Cisco ASA, displayed by show conn, contains the state of active network connections. This information is stored in RAM and is highly volatile. It will be lost upon reboot, power loss, or if the connections time out. It is a critical piece of evidence that must be collected early in an investigation.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 300-215 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 232 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon