350-201 exam dumps

350-201 practice question 146 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 146

Single answer

A security operations team is using Cisco Secure Endpoint to monitor user behavior alerts. An alert is triggered indicating that a user has downloaded a file from an untrusted source, and the file exhibits behavior consistent with ransomware. What should the team's next action be?

  1. A

    Isolate the affected endpoint from the network immediately to prevent further spread.

  2. B

    Ignore the alert since it might be a false positive and wait for further evidence.

  3. C

    Run a scheduled antivirus scan on the endpoint and take action based on the results.

  4. D

    Quarantine the downloaded file and analyze it in a sandbox environment.

Show answer and explanation

Correct answer: A

Explanation

When dealing with alerts indicating ransomware-like behavior, the immediate priority is to contain the potential threat to prevent lateral movement or further damage. Isolating the endpoint from the network ensures that the suspected ransomware cannot spread, buying time for further analysis and remediation steps.

  • A. Correct.

    Isolating the affected endpoint immediately is the best course of action to prevent the ransomware from spreading to other systems in the network. This is a critical response step when dealing with potentially malicious behavior.

  • B. Incorrect.

    Ignoring the alert is not recommended because ransomware behavior can cause significant damage quickly. Waiting for further evidence could allow the malware to propagate and encrypt more data.

  • C. Incorrect.

    Running a scheduled antivirus scan may provide useful information but is not an immediate action to protect the network. This approach is too slow to address the urgency of the situation.

  • D. Incorrect.

    Quarantining the file and analyzing it in a sandbox is a good secondary action for further investigation, but it doesn't immediately mitigate the risk posed by the potentially compromised endpoint.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam