350-201 exam dumps

350-201 practice question 176 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 176

Select 3

An organization using Cisco Secure Endpoint has detected unusual activity on a host. The security team suspects ransomware behavior. Which steps should the team take to investigate this case effectively?

  1. A

    Analyze the host's quarantine events and file trajectory in Cisco Secure Endpoint.

  2. B

    Immediately isolate the host from the network using Cisco Secure Endpoint's isolation feature.

  3. C

    Delete all suspicious files on the host without verifying their behavior.

  4. D

    Review endpoint detection logs and associated Indicators of Compromise (IOCs) in the Cisco SecureX Threat Response tool.

  5. E

    Conduct a vulnerability scan on the network to identify other potentially affected hosts.

Show answer and explanation

Correct answers: A, B, D

Explanation

Investigating ransomware cases requires a structured approach to identify the root cause, prevent spread, and collect forensic evidence. Analyzing quarantine events and file trajectory, isolating the compromised host, and utilizing threat detection tools like Cisco SecureX Threat Response are critical steps. Deleting files prematurely or focusing on network-wide scans at this stage may hinder investigation and containment efforts.

  • A. Correct.

    Analyzing quarantine events and file trajectory helps identify the origin and propagation method of the suspicious activity, which is critical in ransomware investigations.

  • B. Correct.

    Isolating the host ensures that the potentially compromised system cannot spread the ransomware further across the network.

  • C. Incorrect.

    Deleting files without verifying their behavior can lead to the loss of forensic evidence and may not resolve the root cause of the issue.

  • D. Correct.

    Reviewing endpoint detection logs and IOCs in Cisco SecureX Threat Response provides additional context about the scope and severity of the ransomware activity.

  • E. Incorrect.

    While conducting a vulnerability scan can be useful, it is not an immediate investigative action required during the initial stages of a ransomware case.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam