300-215 Question 200
Select 2During an incident response, a security analyst is tasked with identifying the initial attack vector and containing the threat. Using Cisco Secure Endpoint and Cisco SecureX, the analyst observes unusual file executions on multiple endpoints. Which of the following steps should the analyst prioritize next in the incident response process?
- A
Isolate affected endpoints to prevent further spread of the attack.
- B
Perform a root cause analysis to understand how the threat entered the network.
- C
Initiate recovery processes by restoring affected systems from backups.
- D
Leverage threat intelligence in Cisco SecureX to identify Indicators of Compromise (IoCs).
- E
Notify legal and regulatory authorities about the breach immediately.
Show answer and explanation
Correct answers: A, D
Explanation
The immediate priorities in the incident response process are to contain the threat and prevent further damage. Isolating affected endpoints and leveraging tools like Cisco SecureX to identify IoCs are critical actions at this stage. Root cause analysis, recovery, and regulatory notifications occur in later phases of the process.
- A. Correct.
Correct. Isolating affected endpoints is a containment measure within the incident response process. This prevents the threat from spreading further across the network.
- B. Incorrect.
Incorrect. Root cause analysis is vital but typically occurs during the eradication or lessons learned phase, not as an immediate next step during containment.
- C. Incorrect.
Incorrect. Recovery is a later phase of the incident response process and should only begin after the threat is contained and eradicated.
- D. Correct.
Correct. Using Cisco SecureX to identify IoCs helps in understanding the scope of the attack and aids in containment and eradication efforts.
- E. Incorrect.
Incorrect. Notifying legal and regulatory authorities is a critical step in some incidents but should be done after containment and in accordance with regulatory requirements.