350-201 Question 29
Single answerA financial institution has detected unusual outbound traffic from one of its internal servers. The Security Operations Center (SOC) team has been tasked to respond to this incident. According to the Cisco incident response workflow, what should the team do next after confirming this is a legitimate security incident?
- A
Contain the affected server to prevent further damage.
- B
Conduct a vulnerability assessment across all servers in the network.
- C
Notify law enforcement immediately about the incident.
- D
Perform a root cause analysis to identify the origin of the attack.
Show answer and explanation
Correct answer: A
Explanation
The Cisco incident response workflow emphasizes containment as the immediate next step after confirming an incident. Containment helps to isolate the threat, limit its impact, and protect other systems. Steps like vulnerability assessments, law enforcement notifications, and root cause analysis are performed later in the process, following containment and eradication.
- A. Correct.
Containing the affected server is the immediate next step in the incident response workflow to prevent the spread of the threat and minimize damage.
- B. Incorrect.
Conducting a vulnerability assessment across all servers is part of a broader cybersecurity strategy but not the immediate next step in the incident response process.
- C. Incorrect.
Notifying law enforcement might be necessary depending on regulations or the severity of the incident, but this step usually comes after containment and initial investigation.
- D. Incorrect.
Performing a root cause analysis is important but is typically done after containment and eradication to fully understand the attack and prevent recurrence.