300-215 exam dumps

300-215 practice question 199 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 199

Select 3

A cybersecurity analyst is tasked with responding to a suspected ransomware attack on a company's network. The analyst is using Cisco SecureX to manage the incident. Which of the following steps should the analyst prioritize based on standard incident response processes?

  1. A

    Isolate the infected systems to prevent further spread of the ransomware.

  2. B

    Perform a complete system backup of the infected systems to preserve evidence.

  3. C

    Immediately delete the infected files to stop the ransomware from encrypting more data.

  4. D

    Identify and document the Indicators of Compromise (IoCs) using Cisco Threat Response.

  5. E

    Restore the affected systems from the most recent known good backup.

Show answer and explanation

Correct answers: A, B, D

Explanation

In a ransomware incident, standard incident response processes emphasize containment, evidence preservation, and analysis. Isolating infected systems prevents further damage, while backing up affected systems ensures evidence is intact for forensic analysis. Identifying IoCs using tools like Cisco Threat Response helps in understanding and mitigating the attack. Deleting infected files prematurely or restoring systems without proper analysis can lead to incomplete remediation and further risks.

  • A. Correct.

    Isolating the infected systems is critical to containing the ransomware and stopping its spread across the network.

  • B. Correct.

    Performing a system backup preserves evidence for forensic analysis and can help in understanding the scope of the attack.

  • C. Incorrect.

    Deleting infected files without proper analysis or backups can result in the loss of valuable evidence and may hinder recovery efforts.

  • D. Correct.

    Identifying and documenting IoCs using Cisco Threat Response is essential for determining how the attack occurred and preventing future incidents.

  • E. Incorrect.

    Restoring systems should only occur after the incident has been thoroughly analyzed and the threat has been eradicated. It is not a priority during the initial response phase.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam