200-201 exam dumps

200-201 practice question 24 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 24

Single answer

During a routine threat-hunting session, a cybersecurity analyst notices abnormal outbound traffic from a specific endpoint. Upon further investigation, the analyst discovers that the endpoint is communicating with an IP address flagged on a threat intelligence feed. What should the analyst do next to effectively continue the threat-hunting process?

  1. A

    Isolate the endpoint from the network immediately to prevent further communication.

  2. B

    Investigate the processes and applications running on the endpoint to identify the source of the communication.

  3. C

    Block the flagged IP address in the firewall to stop outbound traffic.

  4. D

    Create a new threat-hunting hypothesis focused on similar endpoints within the network.

Show answer and explanation

Correct answer: B

Explanation

The goal of threat hunting is to proactively identify and understand potential threats within the network. When abnormal activity is detected, the priority is to investigate the source and gather evidence to inform containment and mitigation strategies. Investigating processes and applications running on the endpoint is the most logical and effective next step in this scenario.

  • A. Incorrect.

    While isolating the endpoint can be necessary in some scenarios, it is not the immediate next step in the threat-hunting process. Threat hunting prioritizes investigation over immediate containment to understand the scope and root cause.

  • B. Correct.

    Investigating the processes and applications running on the endpoint aligns with the core principles of threat hunting. This step allows the analyst to identify the source of the abnormal behavior and gather critical information to inform further actions.

  • C. Incorrect.

    Blocking the flagged IP address might mitigate immediate risk, but it does not fulfill the investigative goal of threat hunting. Without understanding the root cause, the threat could persist or reappear.

  • D. Incorrect.

    Creating a new threat-hunting hypothesis is important for expanding the scope of the investigation after gathering initial findings, but it is not the immediate next step when abnormal activity is identified.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam