300-215 exam dumps

300-215 practice question 110 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 110

Select 2

During an incident response, a security analyst is using Cisco Secure Endpoint to investigate a malware outbreak in an enterprise network. The analyst observes that a critical file associated with the malware is still active on several endpoints. Which of the following actions should the analyst take next to contain the threat effectively?

  1. A

    Use Cisco Secure Endpoint to isolate the affected endpoints from the network.

  2. B

    Manually delete the suspected malware file from all affected endpoints.

  3. C

    Initiate a file quarantine for the suspected malware using Cisco Secure Endpoint.

  4. D

    Deploy an updated antivirus signature to the endpoints using Cisco Secure Endpoint.

  5. E

    Shut down the corporate network to prevent further spread of the malware.

Show answer and explanation

Correct answers: A, C

Explanation

In this scenario, the priority is to quickly contain the malware to prevent further spread and damage. Isolating affected endpoints from the network and quarantining the suspected file using Cisco Secure Endpoint are effective and scalable containment measures. These actions ensure that the threat is neutralized while minimizing disruption to the organization and allowing further analysis.

  • A. Correct.

    Isolating the affected endpoints prevents the malware from communicating with other devices on the network, effectively containing the threat's spread.

  • B. Incorrect.

    Manually deleting the file is not effective or scalable in a corporate environment, and it may miss other malicious artifacts or processes associated with the malware.

  • C. Correct.

    Initiating a file quarantine ensures that the suspected malware file is rendered harmless while preserving it for further forensic analysis.

  • D. Incorrect.

    Deploying updated antivirus signatures is a valid step, but it does not immediately contain the threat. This action is more suitable for later in the response process.

  • E. Incorrect.

    Shutting down the entire corporate network is an extreme measure that can cause significant business disruption and is not recommended unless absolutely necessary.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam