ETExamTower
300-215Updated 1d ago · Sep 4, 2026

Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)

134 questions across 1 topics, with suggested answers, explanations where available, and imported community discussion. The first 13 questions are free to preview.

Topics

#TopicQuestionsFree
1Forensics Techniques13413

Preview

13 of 134 accessible
Question 1 · Forensics Techniques Open

What is the anti-forensics technique known as steganography?

Answer: D Steganography conceals malicious files or data within ordinary-looking or unsuspecting places, reducing the likelihood that their presence will be noticed during examination.
Question 2 · Incident Response Processes Open

An employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?

Answer: A A root cause analysis records the initiating event that enabled the incident. The phishing email containing the malicious hyperlink led to the employee’s click and subsequent malware download; SIEM alarms and team alerts are detection events rather than the underlying cause.
Question 3 · Incident Response Processes Open

An incident response team recommends changes after reviewing a recent compromise in which: - A large number of events and logs were involved. - Team members could not identify anomalous behavior and escalate it promptly. - Several network systems were affected because detection was delayed. - Security engineers mitigated the threat and restored systems to a stable state. - The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase. Which two recommendations should be made to improve the incident response process? (Choose two.)

Answer: C, E Automated collection and contextualization of system events and logs helps analysts detect anomalous behavior promptly amid high event volumes. A revised incident-handling playbook and checklist establishes agreed roles, responsibilities, and identification steps before an incident, helping ensure the necessary information is gathered and reducing the risk of recurrence.