300-215 exam dumps

300-215 practice question 202 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 202

Select 2

A security operations team is alerted to a potential ransomware infection on an employee's workstation. The team initiates the organization's incident response plan and begins containment procedures. Which of the following actions should the team perform as part of the containment phase?

  1. A

    Disconnect the affected system from the network to prevent further spread.

  2. B

    Shut down the affected system immediately to stop the ransomware process.

  3. C

    Capture a memory dump for forensic analysis before taking further action.

  4. D

    Apply patches to all systems in the network to close potential vulnerabilities.

  5. E

    Redirect the affected system's traffic to a sinkhole for monitoring.

Show answer and explanation

Correct answers: A, C

Explanation

The containment phase of incident response involves isolating the affected system to prevent further damage and collecting critical forensic evidence for analysis. Disconnecting the system and capturing a memory dump are appropriate actions to achieve these goals, while shutting down the system or redirecting traffic may hinder the investigation process or be irrelevant for ransomware cases.

  • A. Correct.

    Disconnecting the affected system from the network is a critical containment step to prevent the ransomware from spreading to other devices.

  • B. Incorrect.

    Shutting down the system immediately is not recommended as it may destroy volatile data, such as memory artifacts, that could be useful for forensic analysis.

  • C. Correct.

    Capturing a memory dump allows the team to preserve volatile data, such as processes and encryption keys, which may be important for investigation and response.

  • D. Incorrect.

    Applying patches is a proactive step but not directly part of the immediate containment phase, which focuses on isolating and limiting the impact of the incident.

  • E. Incorrect.

    Redirecting the affected system's traffic to a sinkhole is more appropriate for specific types of threats (e.g., botnets) but is not typically used for ransomware containment.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam