Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 4 Question 111 Discussion

The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling this event?
C) Collect public information on the malware behavior.
A) Isolate the infected endpoint from the network.
B) Perform forensics analysis on the infected endpoint.
D) Prioritize incident handling based on the impact.

Cisco 200-201 Exam - Topic 4 Question 111 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 111
Topic #: 4
[All 200-201 Questions]

The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling this event?

Show Suggested Answer Hide Answer
Suggested Answer: C

According to the NIST Computer Security Incident Handling Guide, the next step in handling an event after confirming a potential indicator of compromise on an endpoint is to collect public information on the malware behavior. This step involves searching for information from various sources, such as antivirus vendors, security blogs, threat intelligence feeds, and online forums, to learn more about the characteristics, capabilities, and impact of the malware. This information can help the SOC team to identify the type, severity, and scope of the incident, as well as to determine the appropriate response actions and mitigation strategies. Isolating the infected endpoint, performing forensics analysis, and prioritizing incident handling are subsequent steps that follow after collecting public information on the malware behavior.Reference:

Computer Security Incident Handling Guide

SP 800-61 Rev. 2, Computer Security Incident Handling Guide


Contribute your Thoughts:

0/2000 characters
Thurman
8 months ago
Wait, is isolating really the first thing? Seems risky!
upvoted 0 times
...
Marya
9 months ago
A makes sense, but what if it spreads before isolation?
upvoted 0 times
...
Silva
9 months ago
Definitely A, isolating is crucial!
upvoted 0 times
...
William
9 months ago
I think B is more important, gotta analyze first.
upvoted 0 times
...
Sherron
9 months ago
C is useful too, but not the immediate step.
upvoted 0 times
...
Broderick
9 months ago
Collecting information on the malware sounds useful, but I wonder if we should act faster. Is option C really the next step?
upvoted 0 times
...
Reena
10 months ago
I feel like we practiced a similar question where isolating the endpoint was emphasized first. A seems like the best answer here.
upvoted 0 times
...
Jamal
10 months ago
I'm not entirely sure, but I remember something about forensics being important too. Maybe B is the right choice?
upvoted 0 times
...
Long
10 months ago
I think isolating the infected endpoint is crucial to prevent further spread, so I might go with option A.
upvoted 0 times
...
Isaiah
10 months ago
I'm a bit confused on the best approach here. Should we focus on forensics analysis or just collect public information on the malware first? I'll need to think this through carefully.
upvoted 0 times
...
Bambi
11 months ago
Isolating the infected endpoint makes sense to me. That way, we can prevent the malware from impacting other systems while we investigate further.
upvoted 0 times
...
Elinore
11 months ago
Okay, I think the key here is to follow the NIST incident handling process. Isolating the infected system seems like the logical next step to contain the threat.
upvoted 0 times
...
Brice
11 months ago
Hmm, I'm not entirely sure about this one. I'll need to review the NIST guide more closely to determine the proper next step.
upvoted 0 times
...
Elouise
11 months ago
This seems straightforward - the NIST guide would likely recommend isolating the infected endpoint to prevent further spread of the malware.
upvoted 0 times
...
Chauncey
1 year ago
Prioritizing incident handling? Sounds like a job for the incident response team - the A-Team of cybersecurity!
upvoted 0 times
Lucy
11 months ago
A) Isolate the infected endpoint from the network.
upvoted 0 times
...
...
Gregoria
1 year ago
I believe prioritizing incident handling based on the impact is important to minimize damage.
upvoted 0 times
...
Margurite
1 year ago
Collecting public info on the malware behavior? Pfft, who needs that when you've got the SOC team on the case!
upvoted 0 times
...
Burma
1 year ago
Isolating the infected endpoint? That's like putting a band-aid on a gunshot wound.
upvoted 0 times
Mari
11 months ago
D) Prioritize incident handling based on the impact.
upvoted 0 times
...
Judy
1 year ago
B) Perform forensics analysis on the infected endpoint.
upvoted 0 times
...
Helga
1 year ago
A) Isolate the infected endpoint from the network.
upvoted 0 times
...
...
Rikki
1 year ago
Performing forensics analysis on the infected endpoint could also provide valuable insights.
upvoted 0 times
...
Keena
1 year ago
I agree with Farrah, isolating the endpoint is crucial to prevent further spread.
upvoted 0 times
...
Farrah
1 year ago
I think the next step should be isolating the infected endpoint.
upvoted 0 times
...
Pamela
1 year ago
Isolate the infected endpoint? That's a no-brainer! Gotta contain the threat before it spreads like wildfire.
upvoted 0 times
Alesia
1 year ago
D) Prioritize incident handling based on the impact.
upvoted 0 times
...
Gayla
1 year ago
B) Perform forensics analysis on the infected endpoint.
upvoted 0 times
...
Candra
1 year ago
A) Isolate the infected endpoint from the network.
upvoted 0 times
...
...

Save Cancel