350-201 exam dumps

350-201 practice question 148 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 148

Select 3

You are a cybersecurity analyst monitoring user behavior in Cisco Secure Endpoint. You receive an alert that a user account has initiated multiple failed login attempts followed by a successful login from a foreign IP address. What should be your next action based on this user behavior alert?

  1. A

    Initiate an immediate password reset for the affected user account.

  2. B

    Investigate the foreign IP address to determine its reputation and if it is associated with malicious activity.

  3. C

    Ignore the alert since the user eventually logged in successfully.

  4. D

    Suspend the user account and escalate the issue to your incident response team.

  5. E

    Run a malware scan on the user’s endpoint to check for potential compromise.

Show answer and explanation

Correct answers: A, B, D

Explanation

The alert indicates suspicious behavior that could signify account compromise, such as potential credential theft or brute force attacks from a foreign IP address. The correct actions involve securing the account through a password reset, investigating the source of the suspicious activity, suspending the account to prevent further malicious access, and escalating the issue to the incident response team for further analysis. Ignoring the alert or focusing solely on endpoint scans would fail to address the root cause of the incident.

  • A. Correct.

    Initiating a password reset ensures that if the account has been compromised, the attacker is locked out. This is a proactive step to secure the account.

  • B. Correct.

    Investigating the foreign IP address is crucial to determine if it is connected to malicious activity, which could indicate a potential breach.

  • C. Incorrect.

    Ignoring the alert is not a valid action in a cybersecurity context. Even though the login was successful, the pattern of failed logins followed by a foreign IP login is highly suspicious and requires action.

  • D. Correct.

    Suspending the user account and escalating the issue to the incident response team ensures that any potential ongoing attack can be mitigated while further investigation is conducted.

  • E. Incorrect.

    Running a malware scan on the user’s endpoint is generally a good cybersecurity practice, but it is not the immediate priority in this scenario as the alert relates to account behavior, not endpoint compromise.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam