IT認証試験問題集
毎月、GOWUKAKUは1500人以上の受験者が試験準備を助けて、試験に合格するために受験者にご協力します
 ホームページ / 300-215 問題集  / 300-215 問題練習

Cisco 300-215 問題練習

Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) 試験

最新更新時間: 2026/09/21

【秋学習応援セール|10月限定キャンペーン】:300-215 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。

実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。

さらに試験準備時間の35%を節約するには、300-215 問題集を使用してください。

 / 7

Question No : 1
Refer to the exhibit.



According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

正解:
Explanation:
From the Wireshark capture:
A (iraniansk.com): This domain is not a known legitimate resource and is hosting a suspicious file named “Fy.exe,” strongly indicative of a malware distribution domain.
D (Fy.exe): The Content-Disposition: attachment; filename="Fy.exe" header explicitly signals a binary executable download, a key indicator in Emotet campaigns.
While Content-Type: application/octet-stream (E) is typical of binary data transfers, it is not unique to malware and cannot by itself serve as a strong IoC. The nginx server (B) and cookie/hash string (C) similarly do not uniquely indicate compromise.

Question No : 2
What are YARA rules based upon?

正解:
Explanation:
YARA rules are primarily used for malware classification and detection based on binary pattern matching within files. They describe sequences of bytes, strings, and other file characteristics found in malicious binaries.
The Cisco CyberOps Associate guide explains: "YARA rules operate by inspecting binary data using conditions and string matches to identify specific patterns that indicate known malware samples.".

Question No : 3
DRAG DROP
Drag and drop the capabilities on the left onto the Cisco security solutions on the right.



正解:

Question No : 4
A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file’s behavior.
Which logs should be reviewed next to evaluate this file further?

正解:
Explanation:
If IPS and SIEM logs do not give enough insight into a file's behavior, the next logical step is to review the Antivirus solution logs.
These logs often provide detailed behavior analytics such as:
File actions and access patterns
Registry modifications
File execution history
The Cisco CyberOps guide emphasizes AV logs as critical forensic artifacts for understanding endpoint-based infections, especially when beaconing or suspicious activity is suspected.

Question No : 5
Which tool is used for reverse engineering malware?

正解:
Explanation:
Ghidra is a free and open-source software reverse engineering (SRE) suite developed by the NSA. It includes disassembly, decompilation, and debugging tools specifically designed for analyzing malware and other compiled programs.
The Cisco CyberOps guide references Ghidra as a top tool for reverse engineering binary files during malware analysis tasks, making it ideal for understanding malicious code behavior at a deeper level.

Question No : 6
DRAG DROP
Drag and drop the steps from the left into the order to perform forensics analysis of infrastructure networks on the right.



正解:


Explanation:
Reference: https://subscription.packtpub.com/book/networking_and_servers/9781789344523/1/ch01lvl1sec12/network-forensics-investigation-methodology

Question No : 7
Refer to the exhibit.



What should be determined from this Apache log?

正解:
Explanation:
The error logs indicate multiple PKCS12 and ASN.1 decoding errors, such as:
PKCS12 routines:PKCS12_parse:mac verify failure
rsa routines:old_rsa_priv_decode:RSA lib
PKCS12 routines:PKCS12_key_gen_uni:malloc
These specific errors most commonly occur when:
The private key does not correspond to the certificate being used.
There is a mismatch between the public and private key pair required for SSL handshakes.
This is a well-documented condition in Apache SSL configuration issues and explicitly covered under TLS/SSL troubleshooting sections in cybersecurity operations contexts. The Cisco CyberOps guide also notes that SSL errors with key verification usually result from "improper key/certificate pairing" rather than file corruption or missing modules.
Thus, the correct answer is:
B. The private key does not match with the SSL certificate.

Question No : 8
Refer to the exhibit.



Which two actions should be taken as a result of this information? (Choose two.)

正解:
Explanation:
The XML (STIX/CybOX format) details an email-based threat indicator. Specifically:
The email address contains “@state.gov” (not exact match, so blocking all @state.gov would be overbroad).
The attachment is a PDF file with a specified MD5 hash: cf2b3ad32a8a4cfb05e9dfc45875bd70.
The attachment size is 87022 bytes.
From a threat mitigation perspective:
A is correct: Updating AV to block or flag files matching the malicious hash is a standard response.
D is correct: The email address context and hash together provide a precise rule for blocking―this prevents false positives.
Incorrect options:
B overreaches by blocking an entire domain without confirming threat context.
C would stop all PDFs, which is impractical.
E is incorrect; there is no indication that the hash appears in the subject line.

Question No : 9
Refer to the exhibit.



A security analyst notices unusual connections while monitoring traffic.
What is the attack vector, and which action should be taken to prevent this type of event?

正解:
Explanation:
The exhibit shows multiple ARP reply packets with the same IP addresses (192.168.51.105 and 192.168.51.201) being mapped to different MAC addresses, which triggers the message: "duplicate use of [IP] detected". This is a strong indicator of an ARP spoofing (or poisoning) attack.
ARP spoofing occurs when a malicious actor sends falsified ARP messages to associate their MAC address with the IP address of another host. This misleads other devices on the network and allows interception or redirection of traffic.
The Cisco CyberOps Associate guide specifically recommends configuring port security on switches as a method to mitigate ARP spoofing, by limiting the number of MAC addresses allowed per port or statically assigning legitimate MAC addresses to switch ports.

Question No : 10
DRAG DROP
Drag and drop the cloud characteristic from the left onto the challenges presented for gathering evidence on the right.



正解:

Question No : 11
Refer to the exhibit.



Which type of code created the snippet?

正解:
Explanation:
The syntax in the code snippet includes:
On Error Resume Next C a classic VBScript error-handling directive.
function ... end function structure.
Use of Mid(), Chr(), and Asc() functions C all commonly used in VBScript for string manipulation.
CInt() for conversion C typical in VBScript.
These characteristics align exactly with VBScript, which is frequently used in malicious macros and obfuscated payloads for malware distribution, as covered in the Cisco CyberOps Associate curriculum when analyzing scripts and encoded threats.

Question No : 12
Refer to the exhibit.



According to the SNORT alert, what is the attacker performing?

正解:
Explanation:
The alert clearly identifies ET SCAN DirBuster Web App Scan in Progress, referencing SID 2008186, which is a Snort signature that specifically detects DirBuster activity. DirBuster is a well-known tool used for brute-forcing hidden directories and files on web servers.
The Cisco CyberOps Associate guide and OWASP both identify directory brute-forcing as a reconnaissance technique to find unprotected or misconfigured endpoints on web applications, typically prior to launching deeper attacks.
Therefore, the correct interpretation of the alert is:
C. brute-force attack against directories and files on the target webserver.

Question No : 13
Refer to the exhibit.



What do these artifacts indicate?

正解:
Explanation:
From the exhibit, the first artifact (PE32 executable from syracusecoffee.com) and the second artifact (HTML from qstride.com) suggest a staged malware delivery method. The executable and the HTML file are linked to different domains, often indicating redirection or multi-stage infection strategies, which is common in phishing or malvertising campaigns.
The Cisco guide explains this tactic as: “One file may appear benign but can initiate downloads or connections to external resources to fetch additional payloads or redirect users”. This pattern of domain redirection strongly supports Option B.

Question No : 14
An engineer received a call to assist with an ongoing DDoS attack. The Apache server is being targeted, and availability is compromised.
Which step should be taken to identify the origin of the threat?

正解:
Explanation:
The best immediate step during a DDoS attack against an Apache web server is to inspect the access logs, which will show which IP addresses are making requests, their frequency, and potential patterns of abuse. As covered in the Cisco CyberOps material, "Apache logs can reveal the IPs responsible for flooding the service with requests". The command sudo tail -100 /var/log/apache2/access.log allows quick review of recent activity.

Question No : 15
Which magic byte indicates that an analyzed file is a pdf file?

正解:
Explanation:
The magic number (also known as a magic byte) is a sequence of bytes used to identify the format of a file.
For PDF files, the standard magic number is:
25 50 44 46, which translates to %PDF in ASCII.
Option C (255044462d) begins with 25 50 44 46, confirming it's a PDF file signature. This is a key forensic detail when performing file type identification and validation of potentially obfuscated or renamed files.

 / 7