350-201 exam dumps

350-201 practice question 175 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 175

Select 3

You are a cybersecurity analyst at a financial institution and receive an alert about suspicious login attempts from multiple IP addresses targeting a critical database server. Based on Cisco's guidelines for investigating common types of cases, which steps should you take to investigate and validate the incident?

  1. A

    Correlate the suspicious IP addresses with known threat intelligence feeds to identify potential malicious actors.

  2. B

    Immediately block all the IP addresses in the firewall without additional investigation.

  3. C

    Review server access logs to identify patterns or anomalies in the login attempts.

  4. D

    Perform a packet capture on the network segment containing the database server to analyze live traffic.

  5. E

    Reboot the database server to ensure it is not compromised.

Show answer and explanation

Correct answers: A, C, D

Explanation

To investigate and validate a cybersecurity incident, it is essential to gather evidence systematically and analyze it to confirm whether the activity is malicious. Steps such as correlating IP addresses with threat intelligence, reviewing access logs for anomalies, and analyzing live network traffic through a packet capture are effective in identifying and understanding the nature of the threat. Actions such as blocking IPs or rebooting systems should only be taken after proper analysis to avoid unnecessary disruptions or loss of evidence.

  • A. Correct.

    Correlating IP addresses with threat intelligence feeds is a critical step in identifying whether the activity is associated with known malicious actors or previously reported threats.

  • B. Incorrect.

    Blocking all IP addresses without further investigation could disrupt legitimate business operations and may cause unnecessary downtime. Proper validation is essential before taking such action.

  • C. Correct.

    Reviewing server access logs is a fundamental step in identifying patterns, such as repeated failed login attempts or access from unusual locations, which can help validate the incident.

  • D. Correct.

    Performing a packet capture helps in analyzing live traffic to detect any malicious payloads or unusual activity targeting the server, providing deeper insights into the potential attacker's behavior.

  • E. Incorrect.

    Rebooting the server without understanding the nature of the attack could disrupt services, erase critical evidence, or even escalate an ongoing attack. This is not a recommended step for investigation.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam