200-901 exam dumps

200-901 practice question 73 of 204

Cisco DevNet Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-901 Question 73

Select 3

Your organization uses Cisco Secure Endpoint to protect endpoints and Cisco Identity Services Engine (ISE) to enforce network access policies. A user reports that their device is being quarantined by ISE due to suspected malware. As part of the investigation, you want to confirm the malware detection and analyze the file for threats using Secure Malware Analytics. What steps should you take to remediate the user's device and remove it from quarantine?

  1. A

    Use Cisco Secure Endpoint to check the device's security events and confirm the malware detection.

  2. B

    Submit the suspected malware file to Cisco Secure Malware Analytics for deeper analysis.

  3. C

    Manually remove the user's device from quarantine in ISE without verifying the threat.

  4. D

    Update the endpoint device's policies in Secure Endpoint and apply a new network access policy in ISE.

  5. E

    Request a retrospective alert from Secure Endpoint to track the file's behavior across the network.

Show answer and explanation

Correct answers: A, B, E

Explanation

To effectively remediate a quarantined device, you should confirm the malware detection in Cisco Secure Endpoint, analyze the malware file using Secure Malware Analytics, and gain retrospective visibility into the file's behavior to understand its impact. This approach ensures a comprehensive response while maintaining network security. Removing the device from quarantine or updating policies without verification can leave the network vulnerable.

  • A. Correct.

    Correct: Cisco Secure Endpoint provides detailed logs on security events, which helps verify the malware detection on the user's device.

  • B. Correct.

    Correct: Submitting the suspected file to Cisco Secure Malware Analytics allows for an in-depth analysis of the file to determine its threat level.

  • C. Incorrect.

    Incorrect: Removing the device from quarantine without verifying the threat exposes the network to potential risks and violates security protocols.

  • D. Incorrect.

    Incorrect: Updating policies without verifying the malware or analyzing the file does not address the actual issue and may result in incomplete remediation.

  • E. Correct.

    Correct: Retrospective alerts from Secure Endpoint provide visibility into the malware's past behavior, helping determine the extent of its impact on the network.

Timed practice exam

Take a 200-901 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam