200-201 exam dumps

200-201 practice question 332 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 332

Select 3

Your organization has detected unusual outbound traffic from a workstation, indicating a potential data exfiltration attempt. Following the NIST.SP800-61 incident handling process, what should be your next steps to properly contain and respond to the incident?

  1. A

    Identify and isolate the affected workstation from the network to prevent further data exfiltration.

  2. B

    Delete all suspicious files from the workstation to remove the threat immediately.

  3. C

    Collect relevant logs and forensic evidence from the workstation for further analysis.

  4. D

    Notify the organization's legal and compliance team as part of the incident response procedures.

  5. E

    Reboot the workstation to restore normal operations and eliminate the suspicious activity.

Show answer and explanation

Correct answers: A, C, D

Explanation

Following the NIST.SP800-61 incident handling process, the correct approach includes containing the threat (e.g., isolating the workstation), gathering evidence for analysis, and involving relevant stakeholders like the legal and compliance team. Actions like deleting files or rebooting systems prematurely can compromise the investigation and hinder the response effort.

  • A. Correct.

    This is correct because isolating the affected workstation is part of the containment phase in the NIST.SP800-61 incident handling process. It helps prevent further damage or data loss.

  • B. Incorrect.

    This is incorrect because deleting files may destroy crucial evidence needed for further investigation and analysis, which is essential for the eradication and recovery phases.

  • C. Correct.

    This is correct because collecting logs and forensic evidence supports the analysis and eradication phases, ensuring a thorough understanding of the incident.

  • D. Correct.

    This is correct because notifying the legal and compliance team is part of the communication plan in the incident response process. Their involvement ensures adherence to regulatory requirements.

  • E. Incorrect.

    This is incorrect because rebooting the workstation could disrupt the analysis and forensic process, potentially destroying evidence of the malicious activity.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam