300-215 Question 114
Select 4During an ongoing incident, a malware infection is identified on multiple endpoints within an enterprise network. As an incident responder, you decide to use Cisco AMP for Endpoints to manage the situation. Which of the following actions should you take to contain and remediate the threat effectively?
- A
Isolate the infected endpoints using AMP's quarantine capability to prevent further network communication.
- B
Use AMP's file trajectory feature to trace the malware's origin and propagation path.
- C
Immediately delete the infected files from affected endpoints without further analysis.
- D
Leverage AMP's outbreak control to block file execution and prevent further infections.
- E
Create a custom detection rule in AMP to identify similar threats in the future.
Show answer and explanation
Correct answers: A, B, D, E
Explanation
Responding to a malware incident requires a structured approach to containment, eradication, and prevention. Cisco AMP for Endpoints provides effective tools like endpoint isolation, file trajectory, outbreak control, and custom detection rules to manage such incidents. These steps not only address the immediate threat but also enhance the organization's ability to detect and respond to similar threats in the future.
- A. Correct.
Isolating infected endpoints is a critical first-step containment measure to prevent the malware from communicating with other systems in the network.
- B. Correct.
Tracing the malware’s origin and propagation path using file trajectory helps in understanding the scope of the infection and identifying patient zero.
- C. Incorrect.
Deleting infected files immediately without analysis is not recommended as it may destroy valuable forensic evidence needed to understand the threat and its behavior.
- D. Correct.
Outbreak control is an effective way to block further execution of the malware and reduce the chances of the infection spreading to other endpoints.
- E. Correct.
Creating a custom detection rule helps in identifying and mitigating similar threats in the future, contributing to proactive defense mechanisms.