200-201 exam dumps

200-201 practice question 193 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 193

Single answer

You are a cybersecurity analyst tasked with securing an organization’s network. During an asset inventory process, you discover that several devices on the network are not listed in the organization's asset management database. What is the most critical first step you should take in this situation?

  1. A

    Immediately disconnect the unlisted devices from the network to prevent potential threats.

  2. B

    Notify the organization's management about the unlisted devices for further instructions.

  3. C

    Identify and classify the unlisted devices to determine their purpose and ownership.

  4. D

    Perform a vulnerability scan on the unlisted devices to assess their security posture.

Show answer and explanation

Correct answer: C

Explanation

When unlisted devices are discovered during an asset inventory process, the first priority is to identify and classify them. This ensures you understand their purpose, ownership, and whether they pose a security risk. Premature actions, such as disconnecting devices or scanning them, could lead to operational disruptions or incomplete assessments. Once classified, appropriate measures can be taken to secure or remove unauthorized devices.

  • A. Incorrect.

    Immediately disconnecting the devices could disrupt legitimate business operations if the devices are critical assets. This step should only be taken if the devices are confirmed to be malicious or unauthorized.

  • B. Incorrect.

    While notifying management is important, it is not the first critical step. Understanding the nature of the unlisted devices is necessary before escalating the issue.

  • C. Correct.

    Identifying and classifying the unlisted devices is the most critical first step as it helps determine whether they are legitimate assets, unauthorized devices, or potential threats. This information is foundational for any further actions.

  • D. Incorrect.

    Performing a vulnerability scan is not the first step because you need to first determine whether the devices are authorized and understand their purpose. Scanning unknown devices may also raise privacy or operational concerns.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam