350-201 exam dumps

350-201 practice question 212 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 212

Select 3

A cybersecurity analyst receives an alert indicating abnormal file access patterns on a corporate laptop. The laptop is running Windows 10, and the organization uses Cisco Secure Endpoint for endpoint protection. Which steps should the analyst take to investigate the potential intrusion?

  1. A

    Review the threat detection logs in Cisco Secure Endpoint to identify suspicious processes.

  2. B

    Isolate the laptop from the network to prevent further potential compromise.

  3. C

    Immediately delete any unknown files found on the laptop to eliminate the threat.

  4. D

    Analyze the endpoint's file trajectory and behavior history within Cisco Secure Endpoint.

  5. E

    Run a full antivirus scan using a third-party tool instead of Cisco Secure Endpoint.

Show answer and explanation

Correct answers: A, B, D

Explanation

To investigate a potential endpoint intrusion, it is critical to use the organization's existing security tools, such as Cisco Secure Endpoint, to analyze threat detection logs and file behavior. Isolating the device ensures containment of the threat, and examining the file trajectory aids in understanding and mitigating the attack path. Immediate deletion of files or reliance on third-party tools without using the existing integrated solution can hinder the investigation or introduce inconsistencies.

  • A. Correct.

    Reviewing the threat detection logs in Cisco Secure Endpoint helps identify malicious processes or files associated with the intrusion.

  • B. Correct.

    Isolating the laptop prevents the potential spread of the compromise to other systems in the network.

  • C. Incorrect.

    Deleting unknown files without proper analysis could result in losing critical evidence or mistakenly removing legitimate files.

  • D. Correct.

    Analyzing the file trajectory and behavior history provides insight into the origin and propagation of the potential threat.

  • E. Incorrect.

    While a third-party antivirus scan may provide additional insights, Cisco Secure Endpoint is already integrated into the organization's security framework and should be the primary tool used first.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam