300-220 Exam Questions
140 real 300-220 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1
What is the first step in determining attack tactics, techniques, and procedures using logs?
- Question #2
Memory-resident malware detection is challenging because:
- Question #3
IoT device threat analysis must include: (Choose two)
- Question #4
Effective use of presentation resources to convey findings involves:
- Question #5
The integration of which products would most enhance analytical capabilities for threat hunting?
- Question #6
What is a key advantage of AI in cybersecurity?
- Question #7
How does TaHiTI contribute to cybersecurity practices?
- Question #8
Reverse engineering is used to determine compromises by:
- Question #9
To improve hunt capability and mature in the Threat Hunting Maturity Model, an organization should first:
- Question #10
A runbook or playbook for a detectable scenario should include:
- Question #11
Identifying memory-resident attacks often requires the use of:
- Question #12
The Cyber Kill Chain helps in determining the priority level of attacks by:
- Question #13
Attack remediation strategies should be based on:
- Question #14
Effective tools and configurations for detection should:
- Question #15
Structured threat hunting differs from unstructured threat hunting in that it:
- Question #16
A mitigation strategy for blocking C2 traffic that involves analyzing behavioral patterns is known as:
- Question #17
Endpoint artifacts are crucial for uncovering undetected threats. Which of the following are considered endpoint artifacts? (Choose two)
- Question #18
A delivery method that is commonly used by threat actors but rarely in authorized assessments is:
- Question #19
Selecting the appropriate threat modeling approach for a scenario requires understanding the:
- Question #20
Selecting deception techniques for a scenario involves:
- Question #21
When interpreting data from memory-specific tools, what is crucial to identify?
- Question #22
Identifying analytical gaps using threat hunting methodologies helps in:
- Question #23
To identify unknown gaps in detection, one should:
- Question #24
A tactic that indicates a sophisticated threat actor rather than a commodity malware campaign is:
- Question #25
In cloud-native threat hunting, which AWS service's logs are essential for analysis?
- Question #26
What indicates a successful C2 communication detection using endpoint logs? (Choose two)
- Question #27
Artifacts at which level of the Pyramid of Pain provide the most context about an attack but are also the most challenging to use for attribution?
- Question #28
To attribute a cyber attack to a specific threat actor, analysts primarily look for:
- Question #29
Advancing in the Threat Hunting Maturity Model involves:
- Question #30
What aspect of a threat intelligence report is critical in drawing conclusions about threat actor tactics?
- Question #31
To determine C2 communications from infected hosts, analysts should examine:
- Question #32
How can logs help in identifying the tactics, techniques, and procedures of a threat actor?
- Question #33
What does the Pyramid of Pain illustrate?
- Question #34
Effective communication of threat hunting findings should:
- Question #35
Recommending changes to improve threat hunt efficiency can include: (Choose two)
- Question #36
Threat intelligence handling involves all of the following EXCEPT:
- Question #37
Security countermeasures should:
- Question #38
To advance to the next phase of the Threat Hunting Maturity Model, an organization should:
- Question #39
A recommended change to enhance detection methodology includes: (Choose two)
- Question #40
When constructing a runbook, it is essential to include:
- Question #41
Multiproduct integration accelerates analysis by:
- Question #42
The primary goal of using BURP Suite in code-level analysis is to:
- Question #43
The MITRE ATT&CK framework is primarily used for modeling:
- Question #44
________ involves proactively searching through networks to detect and isolate advanced threats that evade existing security solutions.
- Question #45
When using the MITRE ATT&CK framework to model threats, changes in ________ are critical for understanding evolving attack strategies.
- Question #46
Utilizing threat intelligence effectively means integrating it into ________ processes.
- Question #47
Procedures of a given threat actor can include:
- Question #48
The likelihood of an attack in a given environment can be recognized by:
- Question #49
When analyzing IoT devices, which aspect is critical?
- Question #50
Selecting suspicious activity often involves analyzing session and protocol data. Which protocol is commonly scrutinized for this purpose?