300-215 exam dumps

300-215 practice question 125 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 125

Select 4

An organization is using Cisco SecureX for incident response and has detected unusual outbound traffic from multiple hosts to an unknown external IP address. After initial analysis, it is suspected that the attack vector involves a phishing email that delivered a malicious payload. Which of the following actions should the organization take to determine the attack surface and recommend appropriate mitigation strategies?

  1. A

    Analyze email headers and content to identify the phishing email's source and distribution patterns.

  2. B

    Use Cisco Secure Endpoint to isolate the affected hosts from the network.

  3. C

    Examine firewall logs to identify other hosts communicating with the same external IP address.

  4. D

    Disable outbound traffic to all external IP addresses to prevent further data exfiltration.

  5. E

    Leverage Cisco Threat Response to correlate events and identify any related indicators of compromise (IOCs).

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To effectively determine the attack surface and recommend mitigation, the organization must gather intelligence on the attack vector (phishing email), isolate affected systems, and analyze logs for signs of further compromise. Using tools like Cisco SecureX and Threat Response can enhance the investigation and response process. A targeted approach ensures that operations are not unnecessarily disrupted while containing the threat.

  • A. Correct.

    Analyzing email headers and content can help identify the origin of the phishing email and the extent of its distribution, which is critical for understanding the attack vector.

  • B. Correct.

    Isolating the affected hosts prevents further lateral movement and data exfiltration, which is a key mitigation step.

  • C. Correct.

    Examining firewall logs helps identify other potentially compromised hosts or malicious activity linked to the same external IP address.

  • D. Incorrect.

    Disabling outbound traffic to all external IP addresses is overly aggressive and could disrupt legitimate business operations. A more targeted approach is recommended.

  • E. Correct.

    Cisco Threat Response is designed to correlate events and help identify related IOCs, making it a valuable tool for determining the attack surface and planning mitigation.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam