nerdexam
Cisco

300-215 · Question #65

A cybersecurity analyst is examining a complex dataset of threat intelligence information from various sources. Among the data, they notice multiple instances of domain name resolution requests to…

The correct answer is C. Organization should focus on C2 communication attempts and the sudden increase in outbound. The combination of known-bad DNS lookups and an unusual spike in egress from one internal system strongly indicates active command-and-control and potential data exfiltration. Prioritizing the investigation and containment of that host’s C2 traffic cuts off the attacker’s…

Submitted by the_admin· Mar 6, 2026Incident Response Techniques

Question

A cybersecurity analyst is examining a complex dataset of threat intelligence information from various sources. Among the data, they notice multiple instances of domain name resolution requests to suspicious domains known for hosting C2 servers. Simultaneously, the intrusion detection system logs indicate a series of network anomalies, including unusual port scans and attempts to exploit known vulnerabilities. The internal logs also reveal a sudden increase in outbound network traffic from a specific internal host to an external IP address located in a high- risk region. Which action should be prioritized by the organization?

Options

  • AThreat intelligence information should be marked as false positive because unnecessary alerts
  • BFocus should be applied toward attempts of known vulnerability exploitation because the attacker
  • COrganization should focus on C2 communication attempts and the sudden increase in outbound
  • DData on ports being scanned should be collected and SSL decryption on Firewall enabled to

How the community answered

(61 responses)
  • A
    5% (3)
  • B
    26% (16)
  • C
    57% (35)
  • D
    11% (7)

Explanation

The combination of known-bad DNS lookups and an unusual spike in egress from one internal system strongly indicates active command-and-control and potential data exfiltration. Prioritizing the investigation and containment of that host’s C2 traffic cuts off the attacker’s control channel and stops further loss of data.

Topics

#threat intelligence#indicator of compromise#C2 communication#incident prioritization

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice