350-201 Question 147
Select 3A financial organization uses Cisco Secure Analytics to monitor user behavior. The security team receives an alert indicating that a privileged user has accessed sensitive financial records during non-business hours and downloaded several large files. What is the next appropriate action the team should take?
- A
Investigate the user's activity further by reviewing detailed logs and correlating with other alerts.
- B
Immediately revoke the user's access to sensitive financial records without further investigation.
- C
Notify the user's manager to verify if the activity was authorized.
- D
Isolate the user's workstation from the network to prevent further potential data exfiltration.
- E
Ignore the alert as it may be a false positive.
Show answer and explanation
Correct answers: A, C, D
Explanation
When responding to user behavior alerts, it is important to take a structured approach. Investigating the activity ensures the security team has all relevant details, while notifying the user's manager adds context. Isolating the workstation is a proactive step to mitigate risk if malicious behavior is suspected. Acting without evidence or ignoring the alert can lead to incorrect conclusions or missed threats.
- A. Correct.
Investigating the user's activity is essential to determine the intent and context behind the behavior. This step helps confirm whether the alert is valid or a false positive.
- B. Incorrect.
Immediately revoking access without investigation could disrupt legitimate activity and lead to operational issues. This should only be done after confirming malicious intent.
- C. Correct.
Notifying the user's manager can help verify whether the activity was authorized, providing additional context to the investigation.
- D. Correct.
Isolating the user's workstation is a precautionary measure to prevent further data exfiltration if malicious behavior is confirmed or strongly suspected.
- E. Incorrect.
Ignoring the alert could result in a missed opportunity to prevent a potential security breach. Alerts should always be reviewed and validated.