300-215 exam dumps

300-215 practice question 147 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 147

Select 3

During an investigation of a suspected ransomware attack, you analyze threat intelligence artifacts and identify indicators of compromise (IoCs) pointing to a known ransomware group. The intelligence report suggests the group uses email phishing as their initial attack vector and leverages command-and-control (C2) domains for lateral movement. Based on this intelligence, which response actions should you prioritize to mitigate the threat?

  1. A

    Block the identified C2 domains at the firewall and web proxy.

  2. B

    Quarantine all emails with similar characteristics to the phishing campaign.

  3. C

    Reboot the affected systems to terminate the ongoing ransomware processes.

  4. D

    Perform endpoint isolation for infected hosts to contain further spread.

  5. E

    Deploy patches for known vulnerabilities exploited by the ransomware group.

Show answer and explanation

Correct answers: A, B, D

Explanation

When dealing with an active ransomware attack, immediate response actions should focus on containment and disruption. Blocking C2 domains, quarantining malicious emails, and isolating infected hosts are critical steps to limit the spread and impact of the attack. While patching systems and other preventive measures are important, they are not the priority in the middle of an active incident.

  • A. Correct.

    Blocking the identified C2 domains prevents the ransomware from communicating with its command-and-control infrastructure, which is critical to disrupting its operation.

  • B. Correct.

    Quarantining phishing emails helps prevent further distribution of the malicious payload and reduces the risk of additional users being compromised.

  • C. Incorrect.

    Rebooting systems could terminate processes, but it may also delete valuable forensic evidence. This is not a recommended immediate response action.

  • D. Correct.

    Isolating infected hosts prevents the ransomware from spreading laterally across the network, which is a key containment strategy.

  • E. Incorrect.

    Deploying patches is a good long-term mitigation strategy, but it is not an immediate response action for this active ransomware attack.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam