200-201 exam dumps

200-201 practice question 223 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 223

Select 3

A security analyst is monitoring a network for unusual activity and notices a significant spike in traffic between two internal systems during non-business hours. Upon further investigation, the analyst discovers that the source system is sending large volumes of data to the destination system using an unauthorized protocol. Which of the following actions should the analyst prioritize to determine if this is a security incident?

  1. A

    Examine logs on both systems to identify the process generating the traffic.

  2. B

    Block all traffic between the two systems immediately to stop potential data exfiltration.

  3. C

    Verify if the unauthorized protocol is necessary for any legitimate business function.

  4. D

    Capture and analyze packet data from the network traffic for further investigation.

  5. E

    Notify end-users associated with the systems to confirm if the activity is legitimate.

Show answer and explanation

Correct answers: A, C, D

Explanation

To determine if the network activity is a security incident, the analyst must focus on gathering evidence and understanding the nature of the traffic. Examining system logs, verifying the protocol's legitimacy, and capturing packet data are critical steps in investigating the anomaly. Premature actions, such as blocking traffic or alerting end-users without sufficient evidence, may cause unnecessary disruption or mislead the investigation.

  • A. Correct.

    Examining system logs can reveal critical details about the processes or services causing the traffic, aiding in identifying whether the activity is malicious.

  • B. Incorrect.

    Blocking all traffic immediately can disrupt legitimate operations and is not a prioritized action unless confirmed as malicious activity.

  • C. Correct.

    Verifying if the unauthorized protocol has any legitimate use is essential to rule out false positives before taking further action.

  • D. Correct.

    Capturing and analyzing packet data allows the analyst to understand the content of the traffic and identify potential malicious intent.

  • E. Incorrect.

    Notifying end-users prematurely may lead to unnecessary alarm and is not a direct step in determining if the activity is a security incident.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam