350-201 exam dumps

350-201 practice question 133 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 133

Select 3

A cybersecurity team is dealing with a high-severity phishing incident in which multiple users have reported receiving malicious emails. The team needs to recommend a SOAR workflow to handle this issue efficiently, including escalation and automation. What steps should the SOAR workflow include to resolve the incident effectively?

  1. A

    Automatically extract Indicators of Compromise (IoCs) from reported emails and enrich them with threat intelligence.

  2. B

    Escalate the incident immediately to senior management without performing any automated analysis.

  3. C

    Isolate affected user accounts and block malicious domains using automated playbooks.

  4. D

    Notify all users in the organization about the phishing campaign and provide them with guidelines for identifying phishing emails.

  5. E

    Automatically generate an incident report and close the investigation without involving manual review.

Show answer and explanation

Correct answers: A, C, D

Explanation

The correct SOAR workflow for addressing a phishing incident includes automating the extraction and enrichment of IoCs to quickly assess the threat, isolating affected accounts and blocking malicious domains to contain the attack, and notifying users to raise awareness and mitigate further risks. Escalation should follow initial automated analysis, and manual review ensures the incident is fully resolved. Skipping these steps or prematurely closing the case would weaken the response process.

  • A. Correct.

    This is correct. Automating the extraction of IoCs and enriching them with threat intelligence helps in identifying the scope and severity of the phishing campaign quickly.

  • B. Incorrect.

    This is incorrect. While escalation may be necessary later, skipping automated analysis would delay the resolution and waste valuable time.

  • C. Correct.

    This is correct. Isolating affected accounts and blocking malicious domains are critical steps in containing the incident and preventing further damage.

  • D. Correct.

    This is correct. Informing users about the phishing campaign helps raise awareness, reduces the likelihood of further compromise, and aligns with incident response best practices.

  • E. Incorrect.

    This is incorrect. Automatically closing the investigation without manual review could miss important details or lead to incomplete resolution.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam