300-215 Question 139
Select 3An organization has detected unusual outbound traffic from multiple endpoints, indicating a potential data exfiltration attempt. Using Cisco Secure Network Analytics and Cisco Umbrella, you identify that the traffic is being sent to a suspicious external IP address. What are the most effective mitigation techniques to respond to this incident?
- A
Block the suspicious IP address at the firewall.
- B
Isolate the affected endpoints from the network.
- C
Disable DNS resolution for the suspicious domain using Cisco Umbrella.
- D
Reboot the affected endpoints to terminate any active connections.
- E
Configure Cisco Secure Network Analytics to ignore similar alerts in the future.
Show answer and explanation
Correct answers: A, B, C
Explanation
To effectively respond to the detected data exfiltration attempt, you need to take decisive actions to block the malicious traffic, contain the affected endpoints, and prevent further communication with the suspicious domain. Blocking the IP address at the firewall, isolating the endpoints, and disabling DNS resolution using Cisco Umbrella are all essential mitigation techniques. Rebooting endpoints and ignoring alerts are not appropriate actions in this scenario as they either disrupt investigation or increase the risk of missing future threats.
- A. Correct.
Blocking the suspicious IP address at the firewall prevents further communication with the malicious destination and is a critical containment action.
- B. Correct.
Isolating affected endpoints ensures they cannot continue to send or receive malicious traffic, stopping the spread and further damage.
- C. Correct.
Disabling DNS resolution for the suspicious domain using Cisco Umbrella ensures that endpoints cannot resolve or connect to the malicious domain, effectively cutting off communication.
- D. Incorrect.
Rebooting endpoints does not address the root cause of the issue and may disrupt forensic analysis by potentially erasing volatile evidence.
- E. Incorrect.
Configuring Cisco Secure Network Analytics to ignore similar alerts in the future is counterproductive and increases the risk of overlooking similar incidents.