200-201 exam dumps

200-201 practice question 183 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 183

Select 2

A company’s Security Operations Center (SOC) has implemented an antimalware solution across all endpoints in the network. During a routine security assessment, the SOC analyst discovers that a malware infection bypassed the antimalware software. Which of the following actions should the SOC analyst take to address this issue and prevent future occurrences? (Choose two.)

  1. A

    Ensure that the antimalware software definitions are updated regularly.

  2. B

    Disable the antimalware software and switch to manual threat hunting.

  3. C

    Enable heuristic and behavior-based detection features in the antimalware software.

  4. D

    Whitelist all executable files to prevent further false positives.

  5. E

    Perform a root cause analysis to determine how the malware bypassed the software.

Show answer and explanation

Correct answers: A, C

Explanation

To effectively address a malware infection that bypassed antimalware software, it is essential to ensure that the software is up-to-date with the latest threat definitions and that advanced detection features, such as heuristic and behavior-based analysis, are enabled. These measures improve the software's ability to detect both known and unknown threats. Other options, such as disabling the software or excessive whitelisting, compromise security instead of enhancing it.

  • A. Correct.

    Regular updates to antimalware definitions ensure the software can recognize and defend against the latest known threats. Without updates, outdated definitions leave the system vulnerable to newer malware.

  • B. Incorrect.

    Disabling antimalware software removes an essential layer of defense. Manual threat hunting is not a replacement for automated detection tools.

  • C. Correct.

    Behavior-based detection and heuristic analysis enhance the ability of antimalware software to detect new or unknown threats that may not yet have a signature in the definition database.

  • D. Incorrect.

    Whitelisting all executable files is a poor security practice as it allows any file to execute without inspection, increasing the risk of malware execution.

  • E. Incorrect.

    While root cause analysis is critical to understanding the bypass, it does not directly address prevention through strengthening antimalware defenses.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam