300-215 Question 171
Single answerDuring a forensic investigation using Cisco Secure Endpoint, an analyst discovers that a compromised endpoint is communicating with a known malicious IP address. The analyst wants to preserve evidence while ensuring the endpoint can no longer communicate with the attacker. What is the most appropriate next step in the forensic process?
- A
Quarantine the endpoint using Cisco Secure Endpoint.
- B
Disconnect the endpoint from the network manually.
- C
Capture a memory dump from the endpoint.
- D
Immediately delete the malicious files on the endpoint.
Show answer and explanation
Correct answer: A
Explanation
Quarantining the endpoint using Cisco Secure Endpoint allows the analyst to isolate the system from the network while preserving its current state. This ensures that evidence remains intact for further forensic investigation and prevents additional malicious activity without manual intervention, which could lead to errors or evidence loss.
- A. Correct.
Quarantining the endpoint using Cisco Secure Endpoint is the most appropriate step as it isolates the endpoint from the network while preserving its state for further forensic investigation.
- B. Incorrect.
Manually disconnecting the endpoint from the network is less controlled and could lead to loss of volatile evidence or disrupt the forensic process.
- C. Incorrect.
Capturing a memory dump is an important forensic step but should be done after ensuring the endpoint is isolated from the network to prevent further communication with the attacker.
- D. Incorrect.
Deleting malicious files immediately would destroy potential evidence needed for forensic analysis and should not be done without proper documentation and investigation.