200-201 exam dumps

200-201 practice question 396 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 396

Select 3

A cybersecurity analyst at your organization discovers that an employee has been using company resources to download and share proprietary designs and source code with an external competitor. Which of the following steps should the analyst take to address this intellectual property (IP) breach?

  1. A

    Report the incident to the organization's legal and HR departments immediately.

  2. B

    Notify the competitor involved to request the return of the shared intellectual property.

  3. C

    Preserve all relevant evidence, including logs, emails, and file transfers, for investigation.

  4. D

    Terminate the employee's access to all systems without prior notice or investigation.

  5. E

    Evaluate and implement additional security controls to prevent future intellectual property theft.

Show answer and explanation

Correct answers: A, C, E

Explanation

Intellectual property theft is a serious incident that requires a structured response. Reporting the breach to appropriate internal departments ensures that legal and disciplinary measures are taken correctly. Preserving evidence is crucial for investigations and legal proceedings. Finally, implementing additional security controls reduces the risk of future breaches. Actions such as notifying external entities or immediately terminating access without proper investigation can cause more harm than good and should be avoided.

  • A. Correct.

    Reporting the incident to the organization's legal and HR departments is critical for ensuring a proper and lawful response to the theft of intellectual property.

  • B. Incorrect.

    Notifying the competitor directly is inappropriate and could compromise the investigation. Such actions should only be handled by legal teams if necessary.

  • C. Correct.

    Preserving evidence is essential for investigation and potential legal action. It ensures the organization has a clear record of what occurred.

  • D. Incorrect.

    Immediately terminating the employee's access without proper investigation could lead to legal and operational issues. Access should only be restricted after due diligence.

  • E. Correct.

    Evaluating and implementing additional security measures helps to prevent future incidents and strengthens the organization's overall cyber defenses.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam