350-201 exam dumps

350-201 practice question 13 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 13

Select 3

A security analyst at a retail company notices that several user accounts are exhibiting unauthorized privilege escalation, allowing them to access sensitive customer data. Using the incident response playbook, what steps should be prioritized to address this issue?

  1. A

    Isolate the affected systems to prevent further unauthorized access.

  2. B

    Reboot all servers in the network to reset privileges.

  3. C

    Analyze logs and user activity to identify the source of the privilege escalation.

  4. D

    Implement temporary access controls to restrict administrative privileges.

  5. E

    Inform customers immediately that a data breach has occurred without further investigation.

Show answer and explanation

Correct answers: A, C, D

Explanation

To address unauthorized privilege escalation, isolation of affected systems, investigation of logs to identify the source, and restricting privileges are critical steps. These actions help contain the incident, prevent further exploitation, and provide valuable information for remediation. Rebooting all servers or prematurely notifying customers without proper investigation are not appropriate actions in this scenario.

  • A. Correct.

    Isolating affected systems is a critical step to prevent further exploitation or unauthorized access while the investigation is ongoing.

  • B. Incorrect.

    Rebooting all servers indiscriminately is not a recommended action; it may disrupt legitimate operations and does not address the root cause of the issue.

  • C. Correct.

    Analyzing logs and user activity is essential to identify the origin of the unauthorized privilege escalation and determine how the attacker gained access.

  • D. Correct.

    Implementing temporary access controls ensures that the threat actor cannot further exploit administrative privileges during the investigation.

  • E. Incorrect.

    Informing customers of a breach prematurely without understanding its scope or confirming its occurrence can lead to unnecessary panic and reputational damage.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam