350-201 exam dumps

350-201 practice question 106 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 106

Select 3

Your organization has deployed Cisco Secure Endpoint to protect endpoints against malware and advanced threats. A user reports that their system is running slower than usual, and upon investigation, you discover that an unauthorized process is consuming high CPU resources. How can you use Cisco Secure Endpoint to address this issue?

  1. A

    Use the 'Device Trajectory' feature to analyze the activity of the unauthorized process.

  2. B

    Apply a quarantine policy to immediately isolate the endpoint from the network.

  3. C

    Leverage the 'File Trajectory' feature to determine the origin of the unauthorized process and its associated files.

  4. D

    Manually delete the unauthorized process and its associated files from the endpoint.

  5. E

    Use the 'Threat Response' feature to correlate this activity with other incidents in the network.

Show answer and explanation

Correct answers: A, C, E

Explanation

Cisco Secure Endpoint provides several tools to investigate and respond to unauthorized processes. By using 'Device Trajectory,' you can analyze the process's behavior on the endpoint, while 'File Trajectory' helps trace its origin. Additionally, 'Threat Response' allows you to correlate this event with others in the network, enabling a comprehensive response. These steps ensure a systematic investigation and containment without resorting to manual or disruptive actions prematurely.

  • A. Correct.

    The 'Device Trajectory' feature helps you track the behavior and activity of a process or file on an endpoint, allowing you to identify suspicious or malicious activity.

  • B. Incorrect.

    While isolation might be necessary in some cases, applying a quarantine policy without further investigation could disrupt normal operations unnecessarily.

  • C. Correct.

    The 'File Trajectory' feature allows you to trace the origin and propagation of a file, helping you understand how the unauthorized process was introduced and spread.

  • D. Incorrect.

    Manually deleting files or processes is not recommended, as it can lead to incomplete remediation and might overlook deeper compromises.

  • E. Correct.

    The 'Threat Response' feature helps you correlate this incident with other events in the environment, providing a broader understanding of the threat landscape and enabling more effective containment.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam