350-201 exam dumps

350-201 practice question 167 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 167

Select 3

A security operations center (SOC) analyst is investigating a potential data breach in a company's network. As part of the investigation, the analyst needs to follow incident response processes and procedures to ensure proper handling of evidence and minimize further damage. Which of the following steps should the analyst prioritize as part of the incident response process?

  1. A

    Isolate the affected systems to prevent the spread of the incident.

  2. B

    Immediately delete suspicious files to prevent further damage to the network.

  3. C

    Document all actions taken during the investigation for later analysis.

  4. D

    Notify stakeholders and management about the incident as per the escalation matrix.

  5. E

    Perform a root cause analysis before taking any containment or mitigation actions.

Show answer and explanation

Correct answers: A, C, D

Explanation

The incident response process involves key steps such as containment, documentation, and communication. Isolating affected systems prevents the spread of the threat, while documentation ensures that all actions are traceable and can be reviewed later. Notifying stakeholders ensures that the appropriate parties are aware of the incident and can take necessary actions. However, deleting files prematurely can compromise evidence, and delaying containment for a root cause analysis can allow the threat to escalate.

  • A. Correct.

    Isolating affected systems is a critical containment step to prevent further spread of the incident while maintaining the integrity of evidence.

  • B. Incorrect.

    Deleting suspicious files immediately is not recommended as it could destroy critical evidence required for a forensic investigation.

  • C. Correct.

    Documenting all actions taken is essential for ensuring traceability, accountability, and for preparing reports for post-incident analysis.

  • D. Correct.

    Notifying stakeholders and management as per the escalation matrix is an important communication step in the incident response process.

  • E. Incorrect.

    Performing a root cause analysis before containment is not practical, as containment actions must occur promptly to limit the impact of the incident.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam