300-215 Question 135
Single answerA cybersecurity analyst notices unusual outbound traffic from multiple endpoints in the network. Using Cisco Umbrella, they identify that the traffic is directed to a known malicious domain. After correlating this data with Cisco Secure Network Analytics, it is confirmed that the traffic originates from endpoints infected with malware. What should the analyst recommend as the most effective mitigation technique to contain and respond to this incident?
- A
Block the malicious domain at the DNS level using Cisco Umbrella.
- B
Immediately shut down all affected endpoints to stop further communication.
- C
Quarantine the infected endpoints at the network level using Cisco Secure Network Analytics.
- D
Perform a full re-image of all affected systems to remove the malware.
Show answer and explanation
Correct answer: C
Explanation
The most effective immediate action during an ongoing incident is to contain the threat by isolating the infected endpoints. Cisco Secure Network Analytics allows you to quarantine endpoints, stopping the spread of malware while preserving evidence for forensic analysis. Other options like blocking the domain or re-imaging systems are important but are either insufficient for containment or part of the remediation phase.
- A. Incorrect.
Blocking the malicious domain at the DNS level can prevent further communication with the malicious domain, but it does not address the already infected endpoints or stop lateral movement within the network.
- B. Incorrect.
Shutting down all affected endpoints may disrupt legitimate business processes and does not allow for further forensic analysis or controlled containment.
- C. Correct.
Quarantining the infected endpoints at the network level using Cisco Secure Network Analytics effectively isolates the infected systems, preventing further spread of the malware while maintaining forensic evidence for further analysis.
- D. Incorrect.
Performing a full re-image of affected systems should be part of the remediation phase, but it is not an immediate containment action during an ongoing incident.