350-201 exam dumps

350-201 practice question 10 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 10

Select 2

During an active ransomware attack, a cybersecurity team is following a playbook for incident response. The playbook specifies identifying the affected systems, isolating them from the network, and collecting forensic evidence. Which tools would be most appropriate to use in this scenario?

  1. A

    Cisco Secure Endpoint

  2. B

    Cisco Umbrella

  3. C

    Wireshark

  4. D

    Cisco Secure Malware Analytics (Threat Grid)

  5. E

    Cisco Secure Firewall

Show answer and explanation

Correct answers: A, D

Explanation

The playbook specifies identifying affected systems, isolating them from the network, and collecting forensic evidence. Cisco Secure Endpoint is an effective tool for identifying and isolating compromised devices, while Cisco Secure Malware Analytics (Threat Grid) supports forensic analysis of malware. These tools align closely with the steps outlined in the playbook.

  • A. Correct.

    Cisco Secure Endpoint is a suitable tool for identifying affected systems and isolating them from the network, as it provides endpoint detection and response (EDR) capabilities.

  • B. Incorrect.

    Cisco Umbrella is primarily used for DNS-layer security and blocking malicious domains but does not directly assist in identifying or isolating affected systems or collecting forensic evidence during an active ransomware attack.

  • C. Incorrect.

    Wireshark is a network protocol analyzer that can capture network traffic for analysis but does not provide direct tools for identifying or isolating affected systems or collecting forensic evidence in this scenario.

  • D. Correct.

    Cisco Secure Malware Analytics (Threat Grid) is highly useful for analyzing suspicious files and collecting forensic evidence, which aligns with the playbook's steps for this scenario.

  • E. Incorrect.

    Cisco Secure Firewall is primarily used for perimeter defense and segmentation. While it can block malicious traffic, it is not directly relevant to identifying affected systems or collecting forensic evidence during an active ransomware attack.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam