Conducting Threat Hunting and Defending using Cisco Technologies for CyberO — Free Practice Questions
10 free sample questions from a bank of 73, with the correct answers and explanations. No signup required — start practising right now.
1When recommending changes to improve threat hunting outcomes, it's important to consider:
The potential impact on IT workload and resources
The latest cybersecurity fads
Reducing the scope of the hunt to minimize effort
The preferences of external auditors
Answer: A
The short version
A — Weigh the impact on IT workload and resources. Hunt improvements must be operationally sustainable.
Key concepts in this question
Threat hunting: proactive searching for undetected threats beyond automated alerts.
Operational feasibility: staffing, tool capacity, and maintenance cost constrain what hunts can run.
Recommendation quality: a technically good idea that overwhelms the team fails in practice.
Why A is correct
Hunting recommendations change how analysts, engineers, and systems spend time — new data sources, queries, playbooks, and tuning all consume effort. Factoring workload and resources keeps the proposal realistic, prioritized, and adopted instead of becoming shelfware or burning out the team, which is the core of sound operational decision-making.
Why the others are wrong
B. Chasing cybersecurity fads ignores measured gaps and return on effort.
C. Shrinking hunt scope just to minimize effort weakens coverage and misses threats.
D. External auditor preferences are secondary to actual detection outcomes and internal capability.
300-220 exam tip
Good hunt advice fits the team that must run it — always ask what it costs in people and tools.
2In threat intelligence handling, cataloging is important for:
Making intelligence easily accessible for analysis
Ensuring compatibility with legacy systems
Increasing the speed of the internet connection
Reducing the size of the IT department
Answer: A
The short version
A — Cataloging makes intelligence easily accessible for analysis. Organized intel gets used; scattered intel gets ignored.
Key concepts in this question
Threat intelligence handling: collect, normalize, store, and retrieve indicators and reports.
Cataloging: tagging, indexing, and classifying intel by type, actor, industry, andconfidence.
Analyst workflow: speed of retrieval directly limits speed of detection and response.
Why A is correct
Cataloged intelligence is searchable and correlatable, so analysts can pivot on an IP, hash, or TTP and instantly find related campaigns and context. That accessibility is the whole point of a catalog — turning raw feeds into a usable knowledge base for faster, better decisions.
Why the others are wrong
B. Legacy-system compatibility is an integration concern, not the purpose of cataloging.
C. Cataloging has no effect on internet connection speed.
D. It does not shrink headcount; it makes existing analysts more effective.
300-220 exam tip
Catalog equals findability — if the question asks why organize intel, answer retrievability.
3Memory-resident malware detection is challenging because:
It requires physical access to the server
It can be easily detected with traditional antivirus
It does not modify disk-based files
It only activates during a full moon
Answer: C
The short version
C — Memory-resident malware leaves no disk files to scan. It lives in RAM, so file-based tools miss it.
Key concepts in this question
Memory-resident (fileless) malware: executes in RAM via scripts, injected processes, or legitimate tools.
Traditional antivirus: largely relies on scanning files on disk against signatures.
Detection gap: nothing written to disk means nothing for disk scanners to find.
Why C is correct
Because memory-resident malware never drops a persistent executable — it injects into running processes or uses in-memory scripting — disk-based signature scanning has no artifact to match. Detection therefore requires live memory acquisition and behavioral or runtime monitoring, which is precisely why this class of malware is considered hard to catch.
Why the others are wrong
A. No physical server access is needed; remote memory acquisition and EDR tooling work fine.
B. Traditional antivirus struggles here rather than succeeding, since it depends on disk artifacts.
D. Activation timing is unrelated; the difficulty is the absence of on-disk evidence.
300-220 exam tip
No disk footprint means no disk detection — fileless malware is a memory problem, not a file problem.
4When recommending tools for a given scenario, what factors should be considered?
The cost of the tool only
The vendor's country of origin
Compatibility with existing infrastructure
The tool's color scheme
Answer: C
The short version
C — Check compatibility with existing infrastructure. A tool that cannot plug into the stack will not deliver value.
Key concepts in this question
Tool selection: fit with SIEM, EDR, network, identity, and OS mix.
Interoperability: APIs, log formats, agents, and platform support.
Total cost of ownership: integration effort often exceeds license cost.
Why C is correct
Scenario recommendations succeed only if the tool ingests available telemetry, runs on deployed platforms, and shares data with current controls and workflows. Compatibility determines deployment time, coverage, and analyst adoption, making it the decisive practical factor among the choices.
Why the others are wrong
A. Cost alone ignores capability and fit; the cheapest incompatible tool is wasted money.
B. Vendor country of origin is not a general selection criterion for a scenario.
D. Interface color scheme has no bearing on detection or response outcomes.
300-220 exam tip
Recommend tools that fit the environment — compatibility first, price and looks last.
5The Cyber Kill Chain helps in determining the priority level of attacks by:
Identifying the most expensive software vulnerabilities
Calculating the potential financial loss from an attack
Mapping out the stages of an attack from reconnaissance to actions on objectives
Highlighting the most common types of malware
Answer: C
The short version
C — The Kill Chain maps attack stages from reconnaissance to actions on objectives. Stage position sets priority.
Prioritization logic: later-stage activity means the attacker is closer to impact.
Defensive use: break any link to stop the chain.
Why C is correct
By locating observed activity on the ordered chain, defenders judge how far an intrusion has progressed and which response is urgent — a late-stage installation or C2 session outranks early reconnaissance noise. That stage mapping is exactly how the model turns raw alerts into prioritized action.
Why the others are wrong
A. The model says nothing about software cost or vulnerability pricing.
B. It does not compute financial loss; it sequences attacker steps.
D. It describes phases, not a catalog of malware families.
300-220 exam tip
Kill Chain equals timeline — the further along the chain, the higher the priority.
6Python scripts in threat hunting are used for:
Designing corporate websites
Conducting online marketing campaigns
Automating detection and analysis tasks
Managing employee records
Answer: C
The short version
C — Python scripts automate detection and analysis tasks. They glue data, queries, and logic together.
Key concepts in this question
Hunt automation: repeated log pulls, enrichment, correlation, and alerting.
Python role: API clients, parsers, analytics, and SOAR integrations.
Threat hunting generates repetitive, data-heavy work — querying SIEM/EDR APIs, parsing logs, enriching IOCs, and scoring behavior — and Python is the standard glue for scripting exactly that. Automating these tasks increases hunt frequency, consistency, and coverage while freeing analysts for hypothesis-driven work.
Why the others are wrong
A. Web design is not a hunting use case for Python.
B. Marketing campaigns are unrelated to detection engineering.
D. HR record management is unrelated to threat hunting automation.
300-220 exam tip
Python in hunting means automation — whenever scripts appear, think repeatable detection work.
7Identifying memory-resident attacks often requires the use of:
Memory analysis tools
Network sniffers
Antivirus software
Disk-based forensics tools
Answer: A
The short version
A — Use memory analysis tools. Fileless attacks must be examined where they live: RAM.
Key concepts in this question
Memory forensics: process lists, injected code, hooks, handles, and network sockets from RAM captures.
Tool examples: Volatility-style frameworks and EDR live-memory features.
Why others fail: disk and signature tools lack in-memory visibility.
Why A is correct
Memory-resident attacks hide in running processes and leave little or no disk trace, so only tools that parse RAM images or inspect live process memory can reveal injected threads, hollowed processes, and malicious handles. Memory analysis is purpose-built for exactly that evidence.
Why the others are wrong
B. Network sniffers show traffic but not the in-memory implant causing it.
C. Standard antivirus leans on disk signatures and misses purely in-memory code.
D. Disk-forensics tools examine files and filesystems, where fileless malware deliberately leaves nothing.
300-220 exam tip
Fileless means memory tools — match the evidence location to the tool: RAM crime, RAM lab.
8A comprehensive playbook addresses which phases of incident response? (Choose two)
Detection
Budget planning
Lunch break scheduling
Recovery
Answer: A, D
The short version
A and D — A full playbook covers detection and recovery. It spans finding the incident through restoring normal operations.
Key concepts in this question
Playbook purpose: repeatable, role-assigned steps for the incident lifecycle.
Detection: triage, scoping, and declaring incidents from alerts and hunts.
Recovery: eradicating cause, restoring systems, and verifying return to service.
Why A and D are correct
A comprehensive playbook must open with how an incident is found, validated, and escalated (detection) and close with how services are restored, hardened, and handed back to operations (recovery). Together these endpoints bracket containment, eradication, and lessons learned, giving the team an end-to-end procedure rather than fragments.
Why the others are wrong
B. Budget planning is a management activity, not an incident-response phase.
C. Lunch scheduling is administrative trivia with no place in a response playbook.
300-220 exam tip
Playbooks run from alert to all-clear — anchor answers on detection at the start and recovery at the end.
9What aspect of a threat intelligence report is critical in drawing conclusions about threat actor tactics?
The industry targeted by the attacker
The geographic location of the attacker
The malware delivery method
The specific vulnerabilities exploited
Answer: D
The short version
D — The exploited vulnerabilities reveal actor tactics. Exploit choice shows how the attacker operates.
Key concepts in this question
TTP inference: tools and exploits map to techniques and procedures.
Report conclusions: link observed exploits to known actor playbooks.
Why D is correct
Knowing exactly which vulnerabilities were exploited tells the analyst the entry vector, privilege path, and tooling sophistication, which directly characterizes the actor's methods. Two actors may hit the same industry, but the one burning a fresh RCE versus phishing macros signals very different tactics — so exploit detail is the critical input for TTP conclusions.
Why the others are wrong
A. Target industry describes victimology, not attacker method.
B. Attacker geography is context, not a description of how the attack works.
C. Delivery method matters but is narrower than the full exploit chain that defines the tactic.
300-220 exam tip
Tactics live in the exploit — ask which flaw they used and you learn how they fight.
10Which level of the Pyramid of Pain is most difficult for attackers to change and adapt to when detected?
TTPs (Tactics, Techniques, and Procedures)
Domain names
IP addresses
Hash values
Answer: A
The short version
A — TTPs sit at the top of the Pyramid of Pain. Forcing attackers to change behavior hurts them most.
Key concepts in this question
Pyramid of Pain: ranks indicators from trivial (hashes) to punishing (TTPs) to change.
TTPs: the tactics, techniques, and procedures defining how an actor operates.
Defender goal: impose cost by detecting high-level behaviors, not disposable artifacts.
Why A is correct
IP addresses, domains, and hashes are cheap and rotated in minutes, but abandoning a TTP means retraining operators, rebuilding tooling, and redesigning campaigns. Detection at the TTP level therefore inflicts maximum adaptation cost, which is why it crowns the pyramid.
Why the others are wrong
B. Domains are re-registered cheaply and quickly.
C. IPs are reassigned or proxied with minimal effort.
D. File hashes change with every recompile or packing run.
300-220 exam tip
Pain grows upward — hashes are cheap, TTPs are expensive, so defend at the top.