Home/Practice Test/Cisco/Free 300-220 CBRTHD) v1.0 Practice Test

Free 300-220 CBRTHD) v1.0 Practice Test

Real Exam Style
Questions
Detailed
Explanations
All Domains
Covered
Timed
Practice
4.8919 learner reviews across Microsoft, AWS, and CompTIA tracksVerified purchases
Jump Straight to the 300-220 Questions (No Sign-Up or Credit Card required)
Why choose us
1
Expert Explanations + Sources Master every concept with clarity.
2
2026-Fresh Questions Always current, never outdated.
3
Real Exam Simulation Practice like you'll test.
4
90-Day Free Updates Stay ahead of changes.
5
Start in 60 Seconds No waiting, instant access.

300-220 Practice Questions By Domains

6 domains covered

3. Threat Actor Attribution Techniques

4 free questions available

Start Practice
Premium 30 of 60 free

Practice the full exam, not a sample

Unlock the full bank and practise every domain end to end.

Unlock all 60 questions

Top 10 Most Challenging 300-220 Questions

Question 1
Domain: Threat Hunting Techniques
As a security operations team matures from alert-driven work to proactive threat hunting, which focus best detects adversaries who abuse legitimate credentials and native tools to bypass signature-based systems and standard SIEM alerts?
  • A. Track known bad IPs and domains from threat intel lists
  • B. Watch for antivirus alerts on endpoints for malware signals
  • C. Look for unusual patterns across identities, endpoints, and network data
  • D. Block files with known malicious hashes at the firewall
Question 2
Domain: Threat Hunting Outcomes
A SOC leadership team wants to show how Cisco-based threat hunting adds business value. Which outcome most clearly demonstrates this value?
  • A. More alerts generated by security tools
  • B. Fewer false positives across the SOC
  • C. Earlier detection of attacks before data exfiltration
  • D. Growth in threat intelligence subscriptions
Question 3
Domain: Threat Actor Attribution Techniques
A threat hunting team is trying to attribute several intrusions across organizations to a known actor. Malware and infrastructure vary, and IPs change daily. Which evidence provides the strongest basis for confident attribution?
  • A. Overlapping IP address ranges used in attacks
  • B. Similar malware filenames and hashes
  • C. Consistent attacker tradecraft mapped to MITRE ATT&CK
  • D. Exact timestamps of attack activity
These are the hard ones. There are 50 more. Every question explains why the wrong answers are wrong, with a link to official docs.
Get all 60 questions
Question 4
Domain: Threat Hunting Processes
To make hunts repeatable, scalable, and less dependent on individual analysts, what is the most important process improvement?
  • A. Add more threat intelligence feeds
  • B. Automate alert triage workflows
  • C. Standardize hunt documentation and hypotheses
  • D. Automatically block all suspicious activity
Question 5
Domain: Threat Modeling Techniques
In threat modeling a hybrid environment with on-prem AD and Azure AD, which focus helps identify how an attacker could move from a compromised cloud identity to full on-prem dominance?
  • A. List CVEs affecting domain controllers
  • B. Map trust relationships between identity systems
  • C. Assign CVSS scores to authentication methods
  • D. Analyze packet-level network flows
Question 6
Domain: Threat Hunting Fundamentals
A SOC analyst using Cisco tools wants to distinguish threat hunting from traditional detection engineering. Which activity best exemplifies threat hunting rather than detection engineering?
  • A. Create a SIEM rule to alert on known malicious domains
  • B. Tune EDR alerts to reduce false positives
  • C. Develop a hypothesis to search for credential misuse without producing alerts
  • D. Block IPs based on Talos intelligence
Question 7
Domain: Threat Hunting Techniques
Using Cisco Secure Network Analytics (Stealthwatch) to investigate lateral movement, which behavior most strongly indicates attackers moving laterally using valid credentials?
  • A. High inbound traffic to a web server
  • B. Internal systems authenticating to multiple hosts via SMB in a short span
  • C. DNS queries to newly registered domains
  • D. Repeated HTTP requests to the same external IP
Question 8
Domain: Threat Hunting Outcomes
A SOC repeatedly finds similar attacker behaviors across separate hunts, showing detection gaps. Which change most effectively prevents re-discovery?
  • A. Increase analyst staffing
  • B. Automate hunt execution
  • C. Convert hunt findings into permanent detections
  • D. Conduct more frequent unstructured hunts
Question 9
Domain: Threat Actor Attribution Techniques
During an investigation, analysts note that attackers avoid PowerShell logging, disable AMSI, and prefer WMI for execution. Why is this important for attribution?
  • A. It identifies the malware family used
  • B. It reveals the attacker’s IP infrastructure
  • C. It reflects the attacker’s operational preferences
  • D. It confirms the exploit used for initial access
Question 10
Domain: Threat Hunting Processes
In a structured hunt, after hypotheses are tested and malicious activity is confirmed, what is the next step in the Cisco threat hunting lifecycle?
  • A. Start a new hypothesis immediately
  • B. Document findings and operationalize detections
  • C. Disable all affected user accounts
  • D. Escalate to executive leadership
Disclaimer: Edurely is an independent educational platform. We are not affiliated with, authorized by, endorsed by, or in any way officially connected to Cisco . Full disclaimer
Edurely
Curated By Edurely Team

The Edurely Team comprises certified professionals and subject matter experts dedicated to delivering accurate, up-to-date exam preparation materials. We rigorously review every resource to ensure it aligns with the latest industry standards and certification objectives to help you succeed.