350-201 Question 12
Select 3Your organization has experienced a malware outbreak, and the incident response playbook recommends isolating the infected systems, identifying the malware type, and analyzing its behavior. Which tools should you use to comply with the playbook's requirements?
- A
Cisco Secure Endpoint for endpoint isolation and malware analysis
- B
Wireshark for capturing and analyzing network traffic
- C
Cisco Umbrella for DNS-layer protection and command-and-control blocking
- D
Cisco Secure Malware Analytics (Threat Grid) for dynamic malware behavior analysis
- E
Cisco Secure Firewall for implementing network segmentation
Show answer and explanation
Correct answers: A, B, D
Explanation
The tools needed in this scenario must align with the playbook's specific requirements: endpoint isolation, malware identification, and behavior analysis. Cisco Secure Endpoint provides endpoint isolation and analysis capabilities, Wireshark helps monitor and analyze network traffic related to the malware, and Cisco Secure Malware Analytics (Threat Grid) enables dynamic malware behavior analysis. Cisco Umbrella and Secure Firewall serve other purposes that are not directly relevant to the playbook's outlined actions in this case.
- A. Correct.
Cisco Secure Endpoint provides the ability to isolate compromised endpoints and analyze malware artifacts, which aligns with the playbook's requirements.
- B. Correct.
Wireshark can be used to capture and analyze network traffic, helping identify the spread of the malware and any malicious communications.
- C. Incorrect.
Cisco Umbrella offers DNS-layer protection, but it is not specifically used for isolating infected systems or malware behavior analysis in this scenario.
- D. Correct.
Cisco Secure Malware Analytics (Threat Grid) is designed for dynamic malware behavior analysis, which is relevant to the playbook.
- E. Incorrect.
Cisco Secure Firewall is useful for network segmentation, but it is not directly tied to isolating endpoints or analyzing malware in this context.