350-201 exam dumps

350-201 practice question 36 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 36

Select 4

A security operations team is evaluating its incident response metrics after a recent series of ransomware attacks. They identify that the Mean Time to Detect (MTTD) and Mean Time to Contain (MTTC) were significantly higher than expected. Which of the following actions could help improve these metrics in the future?

  1. A

    Implementing automated threat detection and correlation mechanisms

  2. B

    Increasing the frequency of employee cybersecurity awareness training

  3. C

    Deploying additional network segmentation to limit propagation of attacks

  4. D

    Reducing the number of endpoints monitored to improve focus on critical assets

  5. E

    Establishing a clear incident response plan with defined roles and escalation paths

Show answer and explanation

Correct answers: A, B, C, E

Explanation

Improving incident response metrics, such as MTTD and MTTC, requires a combination of technical improvements (e.g., automation, segmentation) and organizational measures (e.g., training, planning). Options 1, 2, 3, and 5 collectively address these aspects, while option 4 would negatively impact the organization's ability to detect and respond to incidents effectively.

  • A. Correct.

    Automated threat detection can reduce the Mean Time to Detect (MTTD) by identifying threats faster, enabling quicker response.

  • B. Correct.

    Employee training can help in early identification of phishing and ransomware attempts, indirectly improving detection times.

  • C. Correct.

    Network segmentation limits the scope of an attack, simplifying containment processes and lowering the Mean Time to Contain (MTTC).

  • D. Incorrect.

    Reducing the number of endpoints monitored may leave critical systems exposed to threats, which can increase detection and containment times.

  • E. Correct.

    A clear incident response plan ensures that roles and procedures are predefined, reducing delays in detection and containment processes.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam