350-201 Question 10
Select 2During an active ransomware attack, a cybersecurity team is following a playbook for incident response. The playbook specifies identifying the affected systems, isolating them from the network, and collecting forensic evidence. Which tools would be most appropriate to use in this scenario?
- A
Cisco Secure Endpoint
- B
Cisco Umbrella
- C
Wireshark
- D
Cisco Secure Malware Analytics (Threat Grid)
- E
Cisco Secure Firewall
Show answer and explanation
Correct answers: A, D
Explanation
The playbook specifies identifying affected systems, isolating them from the network, and collecting forensic evidence. Cisco Secure Endpoint is an effective tool for identifying and isolating compromised devices, while Cisco Secure Malware Analytics (Threat Grid) supports forensic analysis of malware. These tools align closely with the steps outlined in the playbook.
- A. Correct.
Cisco Secure Endpoint is a suitable tool for identifying affected systems and isolating them from the network, as it provides endpoint detection and response (EDR) capabilities.
- B. Incorrect.
Cisco Umbrella is primarily used for DNS-layer security and blocking malicious domains but does not directly assist in identifying or isolating affected systems or collecting forensic evidence during an active ransomware attack.
- C. Incorrect.
Wireshark is a network protocol analyzer that can capture network traffic for analysis but does not provide direct tools for identifying or isolating affected systems or collecting forensic evidence in this scenario.
- D. Correct.
Cisco Secure Malware Analytics (Threat Grid) is highly useful for analyzing suspicious files and collecting forensic evidence, which aligns with the playbook's steps for this scenario.
- E. Incorrect.
Cisco Secure Firewall is primarily used for perimeter defense and segmentation. While it can block malicious traffic, it is not directly relevant to identifying affected systems or collecting forensic evidence during an active ransomware attack.