Official Bank 0/131

Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) Exam (300-215) - Cisco Exam Questions

Last updated on June 22, 2026

97% Exam Compliance
131 Total Questions
1
Question
Refer to the exhibit.

Exhibit

Refer to the exhibit. A network administrator creates an Apache log parser by using Python. What needs to be added in the box where the code is missing to accomplish the requirement?
Options
A r'\d(1,3),\d(1.3),\d{13}.df{1,3}'
B r'*\b'
C r'\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}'
D r''\b{1-9}[0-9}\b'
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A cybersecurity analyst must identify an unknown service causing high CPU on a Windows server.

What tool should be used?
Options
A Volatility to analyze memory dumps for forensic investigation
B Process Explorer from the Sysinternals Suite to monitor and examine active processes
C SIFT (SANS Investigative Forensic Toolkit) for comprehensive digital forensics
D TCPdump to capture and analyze network packets
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A threat actor has successfully attacked an organization and gained access to confidential files on a laptop. What plan should the organization initiate to contain the attack and prevent it from spreading to other network devices?
Options
A intrusion prevention
B root cause
C attack surface
D incident response
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Which type of record enables forensics analysts to identify fileless malware on Windows machines?
Options
A IIS logs
B file event records
C network records
D PowerShell event logs
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
An attacker embedded a macro within a word processing file opened by a user in an organization’s legal department. The attacker used this technique to gain access to confidential financial data.

Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)
Select 2
Options
A network access control
B removable device restrictions
C controlled folder access
D firewall rules creation
E signed macro requirements
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.