200-201 exam dumps

200-201 practice question 23 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 23

Select 3

During a proactive threat-hunting exercise, a cybersecurity analyst notices a sudden spike in outbound traffic from a previously dormant internal server. The server's logs reveal multiple failed login attempts followed by a successful login from an unusual IP address. Which of the following actions should the analyst prioritize to investigate and contain the potential threat?

  1. A

    Investigate the successful login to identify the source and method of access.

  2. B

    Isolate the affected server from the network to prevent further data exfiltration.

  3. C

    Immediately delete all suspicious logs to prevent attackers from covering their tracks.

  4. D

    Analyze the outbound traffic to determine if sensitive data is being transmitted.

  5. E

    Reboot the server to terminate any ongoing malicious activities.

Show answer and explanation

Correct answers: A, B, D

Explanation

Threat hunting involves proactively identifying and mitigating potential threats. In this scenario, prioritizing actions that preserve evidence (investigating logs, analyzing traffic) and contain the threat (isolating the server) is essential for effective threat response. Deleting logs or rebooting the server without analysis could hinder the investigation and remediation process.

  • A. Correct.

    Investigating the successful login is crucial to understand how the attacker gained access and to identify potential vulnerabilities or compromised credentials.

  • B. Correct.

    Isolating the server is a key containment step to prevent the attacker from continuing to exploit the system or exfiltrate data.

  • C. Incorrect.

    Deleting logs is counterproductive as it removes valuable evidence that could help in understanding the attack and identifying the threat actor.

  • D. Correct.

    Analyzing the outbound traffic can help confirm data exfiltration and provide insights into what information may have been compromised.

  • E. Incorrect.

    Rebooting the server might temporarily disrupt malicious activities, but it could also destroy evidence or give attackers a chance to regain access, making it an inappropriate immediate action.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam