Official Bank 0/131

Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) Exam (300-215) - Cisco Exam Questions

Last updated on June 22, 2026

97% Exam Compliance
131 Total Questions
1
Question
A security team needs to prevent a remote code execution vulnerability. The vulnerability can be
exploited only by sending '${ string in the HTTP request. WAF rule is blocking '${', but system
engineers detect that attackers are executing commands on the host anyway. Which action should the security team recommend?
Options
A Enable URL decoding on WAF.
B Block incoming web traffic.
C Deploy antimalware solution.
D Add two WAF rules to block 'S' and '{' characters separately.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit.

Exhibit

A security analyst notices unusual connections while monitoring traffic. What is the attack vector, and which action should be taken to prevent this type of event?
Options
A DNS spoofing; encrypt communication protocols
B SYN flooding; block malicious packets
C MAC flooding; assign static entries
D ARP spoofing; configure port security
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Refer to the exhibit.

Exhibit

Which type of code is being used?
Options
A Shell
B VBScript
C Python
D BASH
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
An attacker embedded a macro within a word processing file opened by a user in an organization’s legal department. The attacker used this technique to gain access to confidential financial data.

Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)
Select 2
Options
A network access control
B removable device restrictions
C controlled folder access
D firewall rules creation
E signed macro requirements
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A security team received reports of users receiving emails linked to external or unknown URLs that
are non-returnable and non-deliverable. The ISP also reported a 500% increase in the amount of
ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)
Select 2
Options
A scan hosts with updated signatures
B collect logs
C verify the breadth of the attack
D remove vulnerabilities
E request packet capture
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.