200-201 exam dumps

200-201 practice question 188 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 188

Select 3

A Security Operations Center (SOC) analyst receives an alert indicating unusual outbound traffic from a corporate server. The analyst reviews the server logs and discovers that a series of large files were transferred to an unfamiliar external IP address using an encrypted protocol. Which of the following actions should the analyst prioritize to respond to this situation?

  1. A

    Isolate the server from the network to prevent further data exfiltration.

  2. B

    Contact the external IP address owner to request more information.

  3. C

    Perform a forensic analysis on the server to identify the root cause of the incident.

  4. D

    Update firewall rules to block traffic to the external IP address.

  5. E

    Notify the organization's incident response team and escalate the event.

Show answer and explanation

Correct answers: A, C, E

Explanation

When responding to a potential data exfiltration event, the first priority is to contain the impact by isolating the compromised system. From there, forensic analysis is necessary to determine the root cause and scope of the incident. Finally, notifying the incident response team ensures the organization can manage the incident effectively and prevent further damage. Actions like blocking traffic to the external IP or contacting the IP owner may come later but are not as critical in the initial response phase.

  • A. Correct.

    Isolating the server is critical to prevent additional data exfiltration or further compromise by the attacker. This is typically one of the first steps in incident response.

  • B. Incorrect.

    Contacting the external IP address owner is not a priority during initial response. This action may be taken later as part of the investigation process.

  • C. Correct.

    Performing a forensic analysis helps to identify how the breach occurred, what data was accessed, and whether the attacker has left any backdoors. This is a crucial step in mitigating the incident effectively.

  • D. Incorrect.

    While updating firewall rules to block traffic to the external IP address is important, it is not an immediate priority compared to isolating the server and initiating investigation steps.

  • E. Correct.

    Notifying the incident response team ensures that the event is escalated appropriately and that the organization can begin coordinated mitigation and recovery efforts. This is a critical action in incident response.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam