350-201 exam dumps

350-201 practice question 141 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 141

Select 3

Your organization uses a SIEM solution integrated with a User and Entity Behavior Analytics (UEBA) tool to monitor user activities. The SIEM has flagged an alert indicating unusual behavior for a specific user account. The user accessed sensitive financial records at 3:00 AM, performed multiple failed login attempts to an internal server, and attempted to upload files to an external cloud storage service. As a cybersecurity analyst, what should you prioritize when analyzing this anomalous behavior?

  1. A

    Verify if the user’s account has been compromised by checking for unauthorized logins.

  2. B

    Contact the user immediately to confirm if the activities were performed intentionally.

  3. C

    Examine the SIEM logs for any additional correlated alerts or patterns related to the user.

  4. D

    Immediately block the user’s account to prevent further suspicious activity.

  5. E

    Ignore the alert if the user has previously accessed financial records as part of their role.

Show answer and explanation

Correct answers: A, C, D

Explanation

The anomalous activities, such as accessing sensitive records at an unusual time, failed login attempts, and attempted data exfiltration, strongly indicate a potential security breach. The correct course of action involves verifying if the account is compromised, analyzing SIEM data for related alerts, and containing the threat by blocking the account. These steps ensure a thorough investigation while mitigating risk.

  • A. Correct.

    Compromised credentials often result in unusual patterns of activity. Verifying unauthorized logins is critical to determine if a security incident has occurred.

  • B. Incorrect.

    While contacting the user directly may provide insights, it is not the first priority during an investigation as the account could be compromised, and the individual might not respond immediately.

  • C. Correct.

    Examining correlated alerts can help identify a wider pattern of malicious behavior, which is essential for understanding the scope of the incident.

  • D. Correct.

    Blocking the account is a necessary containment step to prevent further damage while the investigation is underway.

  • E. Incorrect.

    Ignoring the alert would be inappropriate as accessing sensitive financial records at unusual hours, combined with other anomalous behaviors, strongly suggests a potential security incident.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam