350-201 exam dumps

350-201 practice question 16 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 16

Select 4

You are working as a cybersecurity analyst for an organization and receive an alert from your SIEM system indicating a potential DoS attack targeting your web server. Which steps from the playbook should you prioritize to effectively mitigate the situation?

  1. A

    Analyze network traffic patterns to confirm the source and nature of the attack

  2. B

    Immediately shut down the web server to stop the attack

  3. C

    Implement rate-limiting on the affected web server interface

  4. D

    Block the malicious IP addresses using an Access Control List (ACL) or firewall rule

  5. E

    Perform a complete restore of the web server from the latest backup

  6. F

    Monitor ongoing traffic to ensure the attack has been mitigated

Show answer and explanation

Correct answers: A, C, D, F

Explanation

In the event of a DoS attack, the primary goal is to confirm the attack's nature and source, then implement targeted mitigation measures such as rate-limiting and blocking malicious IPs. Monitoring post-mitigation ensures that the issue is resolved and allows for further action if the attack continues. Shutting down the server or restoring it are not recommended actions in this scenario, as they either disrupt legitimate traffic or fail to address the actual issue.

  • A. Correct.

    Analyzing network traffic patterns is essential to confirm the attack and identify its source and nature. Without investigation, mitigation actions may be ineffective or overreaching.

  • B. Incorrect.

    Shutting down the web server is not a best practice as it disrupts legitimate traffic and can cause unnecessary downtime.

  • C. Correct.

    Implementing rate-limiting helps minimize the impact of the DoS attack by restricting the number of requests from a single source.

  • D. Correct.

    Blocking the malicious IP addresses is a key step in mitigating the attack by preventing further traffic from known sources of the attack.

  • E. Incorrect.

    Restoring the web server is unnecessary and irrelevant in this scenario as the attack is not related to data integrity or corruption.

  • F. Correct.

    Monitoring ongoing traffic ensures that the mitigation measures are working and that the attack does not persist or evolve.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam