350-201 exam dumps

350-201 practice question 136 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 136

Select 3

A financial organization has recently experienced a phishing attack that resulted in compromised employee credentials. The security team has identified the need to automate the response to such incidents to reduce response time and prevent future occurrences. Which procedural and SOAR workflows should be implemented to address the issue and provide an automated resolution?

  1. A

    Implement an automated playbook to identify and isolate phishing emails based on threat intelligence feeds.

  2. B

    Configure a SOAR workflow to automatically reset passwords for compromised accounts and notify affected users.

  3. C

    Ensure manual review of all phishing emails by the security team before taking any action to avoid false positives.

  4. D

    Automate the integration of phishing detection tools with the email gateway to block malicious emails in real-time.

  5. E

    Escalate all phishing-related alerts directly to high-level management for approval before initiating any response actions.

Show answer and explanation

Correct answers: A, B, D

Explanation

The correct options align with best practices in procedural and SOAR workflows to address phishing attacks. Automated playbooks and integration with email gateways help detect and mitigate phishing emails in real-time, while password resets for compromised accounts reduce risks. Manual reviews and unnecessary escalations undermine the goal of automation and fast response, which SOAR is designed to achieve.

  • A. Correct.

    Correct: Automating the identification and isolation of phishing emails using threat intelligence feeds is a critical step in a SOAR workflow to reduce response time and prevent further distribution of malicious emails.

  • B. Correct.

    Correct: Automatically resetting passwords for compromised accounts and notifying users is a key procedural action to mitigate risks and prevent further unauthorized access.

  • C. Incorrect.

    Incorrect: While manual review can provide accuracy, it negates the purpose of using SOAR for automation and quick response, especially in high-volume phishing attacks.

  • D. Correct.

    Correct: Automating the integration of phishing detection tools with the email gateway ensures real-time protection, reducing the operational burden on the security team.

  • E. Incorrect.

    Incorrect: Escalating all phishing-related alerts to management delays the response process and is counterproductive in a scenario requiring quick action and automation.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam