350-201 exam dumps

350-201 practice question 108 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 108

Select 3

An organization suspects that a host within its network has been compromised and is communicating with a command-and-control (C2) server. As a security analyst, you are tasked with verifying and mitigating the threat. Which of the following actions are most effective in addressing this scenario?

  1. A

    Analyze network traffic logs to identify suspicious connections originating from the host.

  2. B

    Isolate the suspected host from the network to prevent further communication with the C2 server.

  3. C

    Immediately shut down the host to stop all activities on the machine.

  4. D

    Deploy anti-malware software to the host to scan and remove potential threats.

  5. E

    Update the host's operating system and software to the latest patches.

Show answer and explanation

Correct answers: A, B, D

Explanation

When dealing with a suspected compromised host communicating with a C2 server, the priority is to identify the scope of the breach, mitigate the risk of further damage, and remediate the threat. Analyzing traffic logs provides valuable information, while isolating the host ensures containment. Deploying anti-malware helps address the root cause of the issue. Other actions, such as shutting down the host or performing updates, are less effective in this immediate context and can hinder forensic analysis or fail to address the primary threat.

  • A. Correct.

    Analyzing network traffic logs helps identify the nature of the communication, such as the IP address of the C2 server, protocols used, and patterns of data exfiltration. This is crucial for understanding the scope of the compromise.

  • B. Correct.

    Isolating the host from the network prevents further damage, such as data exfiltration or propagation of malware to other systems, while allowing the security team to investigate the issue in a controlled environment.

  • C. Incorrect.

    While shutting down the host might stop malicious activity temporarily, it can also destroy volatile evidence that could have been useful for forensic analysis.

  • D. Correct.

    Deploying anti-malware software is an effective way to detect and remove malware present on the host, thereby mitigating the immediate threat.

  • E. Incorrect.

    Updating the host's operating system and software is a good security practice but is not a direct response to an ongoing threat. It does not address the C2 communication or immediate compromise.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam