300-215 Question 136
Select 4An organization is using Cisco Secure Network Analytics to monitor its network traffic and detect suspicious activities. Recently, a spike in outbound DNS requests to a known malicious domain was identified. As a cybersecurity analyst, which of the following mitigation techniques should you recommend to respond to this alert effectively?
- A
Block the malicious domain using Cisco Umbrella to prevent further DNS queries.
- B
Quarantine the affected endpoint using the Cisco Secure Endpoint platform.
- C
Update firewall rules to block traffic associated with the malicious domain.
- D
Ignore the alert and wait for further evidence before taking action.
- E
Generate an incident report and escalate the issue to the SOC team for further analysis.
Show answer and explanation
Correct answers: A, B, C, E
Explanation
Effective mitigation of a DNS-based threat involves a multi-layered approach. Blocking the malicious domain, isolating the affected endpoint, and updating firewall rules directly address the immediate threat. Meanwhile, generating an incident report and escalating the issue ensures the event is thoroughly investigated and proper follow-up actions are taken. Ignoring the alert is not acceptable in a cybersecurity context, as it can lead to further compromise and damage.
- A. Correct.
Blocking the malicious domain using Cisco Umbrella is an effective first step to prevent further DNS queries to the domain, limiting potential data exfiltration or command-and-control communication.
- B. Correct.
Quarantining the affected endpoint using Cisco Secure Endpoint ensures that the compromised device is isolated from the network, preventing further spread or malicious activity.
- C. Correct.
Updating firewall rules to block traffic associated with the malicious domain adds another layer of defense and ensures that the domain cannot be accessed from other endpoints within the organization.
- D. Incorrect.
Ignoring the alert and waiting for further evidence is not a recommended practice, as timely action is critical in mitigating potential cyber threats.
- E. Correct.
Generating an incident report and escalating the issue to the SOC team ensures proper documentation and allows for further investigation and monitoring of the incident.