350-201 Question 176
Select 3An organization using Cisco Secure Endpoint has detected unusual activity on a host. The security team suspects ransomware behavior. Which steps should the team take to investigate this case effectively?
- A
Analyze the host's quarantine events and file trajectory in Cisco Secure Endpoint.
- B
Immediately isolate the host from the network using Cisco Secure Endpoint's isolation feature.
- C
Delete all suspicious files on the host without verifying their behavior.
- D
Review endpoint detection logs and associated Indicators of Compromise (IOCs) in the Cisco SecureX Threat Response tool.
- E
Conduct a vulnerability scan on the network to identify other potentially affected hosts.
Show answer and explanation
Correct answers: A, B, D
Explanation
Investigating ransomware cases requires a structured approach to identify the root cause, prevent spread, and collect forensic evidence. Analyzing quarantine events and file trajectory, isolating the compromised host, and utilizing threat detection tools like Cisco SecureX Threat Response are critical steps. Deleting files prematurely or focusing on network-wide scans at this stage may hinder investigation and containment efforts.
- A. Correct.
Analyzing quarantine events and file trajectory helps identify the origin and propagation method of the suspicious activity, which is critical in ransomware investigations.
- B. Correct.
Isolating the host ensures that the potentially compromised system cannot spread the ransomware further across the network.
- C. Incorrect.
Deleting files without verifying their behavior can lead to the loss of forensic evidence and may not resolve the root cause of the issue.
- D. Correct.
Reviewing endpoint detection logs and IOCs in Cisco SecureX Threat Response provides additional context about the scope and severity of the ransomware activity.
- E. Incorrect.
While conducting a vulnerability scan can be useful, it is not an immediate investigative action required during the initial stages of a ransomware case.