300-215 exam dumps

300-215 practice question 127 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 127

Select 3

An organization suspects that its internal server infrastructure has been compromised. During the investigation, you identify that the attacker exploited an unpatched vulnerability in the organization's web application and gained access to sensitive data. Which of the following actions should you take to determine the attack surface and recommend appropriate mitigation strategies?

  1. A

    Conduct a vulnerability scan across the organization's web applications to identify unpatched vulnerabilities.

  2. B

    Review server logs to identify unauthorized access attempts and correlate them with known vulnerabilities.

  3. C

    Isolate the web application server from the network to prevent further compromise.

  4. D

    Implement a web application firewall (WAF) to detect and block malicious traffic targeting the application.

  5. E

    Engage with the software vendor to request an immediate patch for the identified vulnerability.

Show answer and explanation

Correct answers: A, B, D

Explanation

To effectively determine the attack surface and recommend mitigation strategies, it is essential to identify all vulnerabilities (via scanning), analyze attack patterns (via server logs), and implement measures to reduce the attack surface (such as deploying a WAF). These steps collectively help in addressing the immediate threat and preventing similar attacks in the future.

  • A. Correct.

    Conducting a vulnerability scan helps identify any other unpatched vulnerabilities that could be part of the attack surface, enabling a comprehensive mitigation strategy.

  • B. Correct.

    Server logs provide critical information about unauthorized access attempts and can help trace the attack vector and determine the attack surface.

  • C. Incorrect.

    While isolating the server could help prevent further compromise, this is a containment action and does not directly determine the attack surface or recommend mitigation strategies.

  • D. Correct.

    Implementing a web application firewall (WAF) is a proactive mitigation measure that can help reduce the attack surface by blocking malicious traffic.

  • E. Incorrect.

    Engaging with the software vendor for a patch is a valid action, but it is not directly related to determining the attack surface or recommending mitigation.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam