| Exam Code/Number: | 300-215Join the discussion |
| Exam Name: | Conducting Forensic Analysis & Incident Response Using Cisco Technologies for CyberOps |
| Certification: | Cisco |
| Question Number: | 187 |
| Publish Date: | Sep 02, 2026 |
|
Rating
100%
|
|
A security team is discussing lessons learned and suggesting process changes after a security breach incident.
During the incident, members of the security team failed to report the abnormal system activity due to a high project workload. Additionally, when the incident was identified, the response took six hours due to management being unavailable to provide the approvals needed. Which two steps will prevent these issues from occurring in the future? (Choose two.)
A system administrator is troubleshooting a Linux server experiencing erratic performance. The server shows high CPU-usage spikes, and the kswapd0 process frequently appears at the top of the top output. Despite adequate memory under normal conditions, available memory occasionally drops. No recent changes in user load or installed applications have been reported. Considering these observations, what should the administrator investigate first?
Refer to the exhibit.
Which determination should be made by a security analyst?
A security analyst receives a notification from SIEM that an internal host has active connections to Tor exit nodes. The analyst investigates SIEM events related to the workstation and identifies that the host scans networks for servers with an opened TCP port 1433 An antivirus scan of the workstation does not determine any suspicious activity Which two actions must the analyst take to mitigate this behavior? (Choose two.)
What is an issue with digital forensics in cloud environments, from a security point of view?