350-201 Question 145
Single answerA financial organization uses Cisco Secure Endpoint to monitor user behavior. An alert is triggered for a user attempting to download sensitive files from a restricted server during non-business hours. What should the security team do next?
- A
Isolate the user's device immediately to prevent further activity.
- B
Escalate the alert to the incident response team for investigation.
- C
Mark the alert as a false positive since no malware was detected.
- D
Analyze historical user behavior and determine if the access attempt is legitimate.
Show answer and explanation
Correct answer: B
Explanation
User behavior alerts require prompt and appropriate action. In this scenario, escalating the alert to the incident response team ensures that the unusual behavior is thoroughly analyzed and responded to, minimizing potential risks. Immediate isolation or dismissal of the alert without investigation could lead to either excessive disruption or missed threats.
- A. Incorrect.
Isolating the user's device immediately may be premature without confirming malicious intent or additional context.
- B. Correct.
Escalating the alert to the incident response team for investigation is the most appropriate action as it prioritizes proper analysis of the behavior and potential risk.
- C. Incorrect.
Marking the alert as a false positive without thorough investigation undermines the security process and could allow malicious activity to go unnoticed.
- D. Incorrect.
Analyzing historical user behavior is a valid step but should be part of the investigation process led by the incident response team rather than the immediate next action.