nerdexam
Cisco

300-215 · Question #17

Refer to the exhibit. Which two actions should be taken as a result of this information? (Choose two.)

The correct answer is A. Update the AV to block any file with hash "cf2b3ad32a8a4cfb05e9dfc45875bd70". D. Block emails sent from [email protected] with an attached pdf file with md5 hash. The XML (STIX/CybOX format) details an email-based threat indicator. The email address contains "@state.gov" (not exact match, so blocking all @state.gov would be The attachment is a PDF file with a specified MD5 hash: cf2b3ad32a8a4cfb05e9dfc45875bd70. The attachment size is…

Submitted by minji_kr· Mar 6, 2026Incident Response Techniques

Question

Refer to the exhibit. Which two actions should be taken as a result of this information? (Choose two.)

Exhibit

300-215 question #17 exhibit

Options

  • AUpdate the AV to block any file with hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
  • BBlock all emails sent from an @state.gov address.
  • CBlock all emails with pdf attachments.
  • DBlock emails sent from [email protected] with an attached pdf file with md5 hash
  • EBlock all emails with subject containing "cf2b3ad32a8a4cfb05e9dfc45875bd70".

How the community answered

(46 responses)
  • A
    70% (32)
  • B
    17% (8)
  • C
    9% (4)
  • E
    4% (2)

Explanation

The XML (STIX/CybOX format) details an email-based threat indicator. The email address contains "@state.gov" (not exact match, so blocking all @state.gov would be The attachment is a PDF file with a specified MD5 hash: cf2b3ad32a8a4cfb05e9dfc45875bd70. The attachment size is 87022 bytes.

Topics

#email security#malware hash#threat blocking#incident response

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice