Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) Exam (300-215) - Cisco Actual Exam Questions
Last updated on May 02, 2026
Refer to the exhibit. A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?
http.request.un matches
tls.handshake.type ==1
tcp.port eq 25
tcp.window_size ==0
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An engineer is analyzing a DoS attack and notices that the perpetrator used a different IP address to hide their system IP address and avoid detection. Which anti-forensics technique did the perpetrator use?
cache poisoning
spoofing
encapsulation
onion routing
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Refer to the exhibit. Which two actions should be taken based on the intelligence information? (Choose two.)
Block network access to all .shop domains
Add a SIEM rule to alert on connections to identified domains.
Use the DNS server to block hole all .shop requests.
Block network access to identified domains.
Route traffic from identified domains to block hole.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An attacker embedded a macro within a word processing file opened by a user in an organization’s legal department. The attacker used this technique to gain access to confidential financial dat a. Which two recommendations should a security expert make to mitigate this type of attack? (Choose two.)
controlled folder access
removable device restrictions
signed macro requirements
firewall rules creation
network access control
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Refer to the exhibit. Which two determinations should be made about the attack from the Apache access logs? (Choose two.)
The attacker used r57 exploit to elevate their privilege.
The attacker uploaded the WordPress file manager trojan.
The attacker performed a brute force attack against WordPress and used SQL injection against the backend database.
The attacker used the WordPress file manager plugin to upload r57.php.
The attacker logged on normally to WordPress admin page.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.