200-201 exam dumps

200-201 practice question 174 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 174

Select 3

A security analyst is investigating an endpoint that has been flagged for suspicious activity. During host-based analysis, the analyst observes an unfamiliar process running on the machine. The process is connecting to an external IP address on an unusual port and consuming a significant amount of CPU resources. Which of the following steps should the analyst prioritize to further investigate and mitigate the issue?

  1. A

    Terminate the suspicious process immediately to stop any potential harm.

  2. B

    Check the process hash against a threat intelligence database to identify if it is malicious.

  3. C

    Analyze the external IP address to determine if it is associated with known malicious activity.

  4. D

    Review the process's parent/child relationships to identify how it was initiated.

  5. E

    Disable network connectivity on the affected host to isolate it from the network.

Show answer and explanation

Correct answers: B, C, D

Explanation

When performing host-based analysis, it is crucial to gather as much evidence as possible about the suspicious activity without prematurely disrupting the environment. Checking the process hash, analyzing the external IP, and reviewing the parent/child process relationships provide valuable insights into the nature and origin of the activity. Immediate actions like terminating the process or isolating the host should generally follow a thorough investigation to ensure the incident is handled effectively and critical evidence is preserved.

  • A. Incorrect.

    Terminating the suspicious process immediately might stop potential harm, but it could destroy evidence crucial for understanding the scope of the attack or identifying the root cause.

  • B. Correct.

    Checking the hash of the process against a threat intelligence database helps identify if the process is known to be malicious, which is a critical step in host-based analysis.

  • C. Correct.

    Analyzing the external IP address can reveal if it is linked to malicious activity, providing further context about the potential threat.

  • D. Correct.

    Reviewing the process's parent/child relationships can help trace how the process was initiated, which is essential for identifying the source of the infection.

  • E. Incorrect.

    Disabling network connectivity can contain the threat, but this step is more appropriate after gathering sufficient evidence to avoid disrupting investigative efforts.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam