350-201 exam dumps

350-201 practice question 224 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 224

Select 3

A company uses a hybrid cloud environment to store sensitive customer data. Recently, the security team received an alert indicating potential data exfiltration from a cloud-based database. What are the appropriate initial steps to investigate the potential data loss in this scenario?

  1. A

    Review cloud access logs to identify unusual login patterns or unauthorized access attempts.

  2. B

    Analyze endpoint activity logs to determine if any local systems accessed the database irregularly.

  3. C

    Manually delete suspicious user accounts in the cloud environment to prevent further access.

  4. D

    Inspect database query logs to identify anomalous data extraction activities.

  5. E

    Verify data integrity by comparing the current database state with the most recent known secure backup.

Show answer and explanation

Correct answers: A, B, D

Explanation

Investigating potential data loss in a cloud environment requires a systematic approach, focusing on identifying unauthorized access and anomalous activities. Reviewing cloud access logs, endpoint activity, and database query logs provides critical information to determine the scope and origin of the incident. Deleting accounts prematurely or verifying backups are not appropriate initial steps.

  • A. Correct.

    Reviewing cloud access logs is a critical step to identify unauthorized access or unusual login patterns, which are common indicators of a potential data breach.

  • B. Correct.

    Analyzing endpoint activity logs helps to establish whether compromised endpoints were used as vectors to access the database, adding valuable context to the investigation.

  • C. Incorrect.

    Manually deleting suspicious user accounts without thorough investigation could disrupt legitimate users and hinder the incident response process. This is not an appropriate initial step.

  • D. Correct.

    Inspecting database query logs enables the security team to pinpoint unusual or unauthorized data extraction activities, making it an essential step in the investigation.

  • E. Incorrect.

    While verifying database integrity is important during a recovery phase, it is not an initial step in the investigation process for potential data loss.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam