100-160 exam dumps

100-160 practice question 109 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 109

Single answer

A company's IT team has implemented endpoint detection and response (EDR) software on all corporate devices to enhance security. Shortly after, the EDR system alerts that an employee's device has been compromised by a suspicious executable file downloaded from an email attachment. What is the MOST appropriate next step for the IT team to take?

  1. A

    Isolate the compromised device from the network immediately.

  2. B

    Delete the suspicious executable file from the compromised device.

  3. C

    Update the EDR software on all corporate devices to the latest version.

  4. D

    Reboot the compromised device to terminate the suspicious process.

Show answer and explanation

Correct answer: A

Explanation

When an endpoint is compromised, the primary goal is to contain the threat to prevent further damage. Isolating the device from the network ensures that the threat cannot propagate to other systems or access sensitive information. Other steps, such as malware removal or forensic analysis, should follow after containment.

  • A. Correct.

    Isolating the compromised device from the network immediately prevents the potential spread of malware or unauthorized access to other systems, making it the most appropriate first step.

  • B. Incorrect.

    Deleting the suspicious executable file may remove the immediate threat but does not address the possibility that other malicious actions have already occurred. This is not the most effective initial step.

  • C. Incorrect.

    Updating the EDR software is a good security practice but is not an immediate response to a detected compromise. This action would not directly address the threat.

  • D. Incorrect.

    Rebooting the device might terminate the suspicious process temporarily, but it does not guarantee removal of the malware and could erase forensic evidence required for investigation.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam