Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 2 Question 112 Discussion

An engineer is investigating a ticket from the accounting department in which a user discovered an unexpected application on their workstation. Several alerts are seen from the intrusion detection system of unknown outgoing internet traffic from this workstation. The engineer also notices a degraded processing capability, which complicates the analysis process. Which two actions should the engineer take? (Choose two.)
C) Disconnect from the network. and E) Take an image of the workstation.
A) Restore to a system recovery point.
B) Replace the faulty CPU.
D) Format the workstation drives.

Cisco 300-215 Exam - Topic 2 Question 112 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 112
Topic #: 2
[All 300-215 Questions]

An engineer is investigating a ticket from the accounting department in which a user discovered an unexpected application on their workstation. Several alerts are seen from the intrusion detection system of unknown outgoing internet traffic from this workstation. The engineer also notices a degraded processing capability, which complicates the analysis process. Which two actions should the engineer take? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: C, E

When suspicious activity is detected on a workstation, immediate steps need to be taken to preserve evidence and prevent further compromise:

Disconnecting the system from the network (C) is crucial to stop potential exfiltration of data or ongoing communications with a command-and-control server. This isolation prevents further spread or damage while preserving the state of the compromised system for further investigation.

Taking an image of the workstation (E) is part of the forensics acquisition process. It involves creating a bit-by-bit copy of the system's disk, which preserves all evidence in its current state. This allows for thorough forensic analysis without affecting the original evidence.

These steps align with the best practices outlined in the incident response and forensics processes (as described in the CyberOps Technologies (CBRFIR) 300-215 study guide). Specifically, in the Identification and Containment phases of the incident response cycle, it's emphasized that isolating the system and preserving evidence through imaging are critical to ensuring both containment of the threat and successful forensic investigation.


Contribute your Thoughts:

0/2000 characters
Nikita
3 days ago
Good point. Let’s focus on preserving data.
upvoted 0 times
...
Barney
8 days ago
Plus, if we format, we lose all evidence.
upvoted 0 times
...
Brynn
13 days ago
Exactly, safety first!
upvoted 0 times
...
Catherin
19 days ago
True, but we need to stop the threat first.
upvoted 0 times
...
Nikita
24 days ago
But what about A? Restoring could fix issues too.
upvoted 0 times
...
Barney
29 days ago
E is crucial for analysis. We need that image!
upvoted 0 times
...
Brynn
1 month ago
I agree, disconnecting helps prevent further damage.
upvoted 0 times
...
Catherin
1 month ago
This is tricky. I think C and E are the best options.
upvoted 0 times
...
Lizette
1 month ago
Wait, why not just format the drives? Isn’t that a quick fix?
upvoted 0 times
...
Lonna
2 months ago
I agree, imaging is crucial before doing anything else!
upvoted 0 times
...
Samira
2 months ago
Restoring to a recovery point might not fix the issue though...
upvoted 0 times
...
Asuncion
2 months ago
Disconnecting from the network seems like a no-brainer.
upvoted 0 times
...
Carlee
2 months ago
Definitely take an image of the workstation first!
upvoted 0 times
...
Mitsue
2 months ago
This reminds me of a practice question where we had to prioritize actions. I feel like disconnecting and imaging the workstation are the most logical steps here.
upvoted 0 times
...
Sharmaine
4 months ago
I think restoring to a recovery point might not be the best option since we don't know how long the issue has been happening.
upvoted 0 times
...
Josphine
4 months ago
I'm not entirely sure, but taking an image of the workstation seems like a safe move to preserve evidence before doing anything else.
upvoted 0 times
...
Noble
4 months ago
I remember something about isolating the system first to prevent further damage, so maybe disconnecting from the network is a good idea.
upvoted 0 times
...

Save Cancel