Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 2 Question 93 Discussion

A security team received reports of users receiving emails linked to external or unknown URLs that are non- returnable and non-deliverable. The ISP also reported a 500% increase in the amount of ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)
A) verify the breadth of the attack
B) collect logs
C) request packet capture
D) remove vulnerabilities
E) scan hosts with updated signatures

Cisco 300-215 Exam - Topic 2 Question 93 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 93
Topic #: 2
[All 300-215 Questions]

A security team received reports of users receiving emails linked to external or unknown URLs that are non- returnable and non-deliverable. The ISP also reported a 500% increase in the amount of ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Jovita
9 months ago
I think scanning hosts should be prioritized too.
upvoted 0 times
...
Viola
9 months ago
Wow, a 500% increase? That's insane!
upvoted 0 times
...
Yaeko
10 months ago
Not sure if removing vulnerabilities is the right move right now...
upvoted 0 times
...
Brinda
10 months ago
Collecting logs is a must!
upvoted 0 times
...
Veronica
10 months ago
Gotta verify the breadth of the attack first!
upvoted 0 times
...
Bea
10 months ago
I feel like requesting packet capture could provide valuable insights, but I can't recall if it fits into the recovery phase specifically.
upvoted 0 times
...
Roxanne
11 months ago
I'm a bit confused about whether we should focus on removing vulnerabilities or scanning hosts first. They both seem important.
upvoted 0 times
...
Kristian
11 months ago
I remember a practice question where collecting logs was emphasized as a key action. It seems like it would help understand the scope of the issue.
upvoted 0 times
...
Octavio
11 months ago
I think verifying the breadth of the attack is crucial, but I'm not entirely sure if that's the best first step in recovery.
upvoted 0 times
...
Peggie
11 months ago
I've got this! Verifying the breadth of the attack and collecting logs are the two actions I would take in the recovery phase. Gotta gather all the evidence to understand what happened and how to prevent it in the future.
upvoted 0 times
...
Ciara
11 months ago
Okay, let's think this through. Verifying the breadth of the attack and collecting logs are definitely important to assess the situation. Removing vulnerabilities could also be a good step to prevent further incidents.
upvoted 0 times
...
Tamesha
11 months ago
Hmm, I'm a bit unsure about this one. I think collecting logs and requesting packet capture would be key to investigate the incident, but I'm not sure about the other options.
upvoted 0 times
...
Nana
11 months ago
This question seems straightforward. I'd focus on verifying the breadth of the attack and collecting logs to understand the scope and impact.
upvoted 0 times
...
Gerry
1 year ago
Removing vulnerabilities is definitely important, but I think it should come a little later in the process. First, they need to get a handle on the situation and contain the damage.
upvoted 0 times
Dominga
1 year ago
Requesting packet capture can also help in analyzing the traffic and identifying any malicious activity.
upvoted 0 times
...
Dominga
1 year ago
I agree, verifying the breadth of the attack and collecting logs should be the first steps to understand the extent of the incident.
upvoted 0 times
...
...
Alberta
1 year ago
Haha, I bet the IT guys are pulling their hair out trying to keep up with that 500% increase in email traffic. Crazy stuff!
upvoted 0 times
...
Myrtie
1 year ago
Requesting packet capture is a great idea too. That data could give the security team valuable insights into the attack vector and help them plug any holes.
upvoted 0 times
Nelida
1 year ago
C) request packet capture
upvoted 0 times
...
Chaya
1 year ago
Requesting packet capture is a great idea too. That data could give the security team valuable insights into the attack vector and help them plug any holes.
upvoted 0 times
...
Maryann
1 year ago
B) collect logs
upvoted 0 times
...
Twana
1 year ago
A) verify the breadth of the attack
upvoted 0 times
...
...
Moon
1 year ago
Verifying the breadth of the attack and collecting logs seem like the obvious next steps to me. Can't really recover from an incident without understanding the full scope of the problem.
upvoted 0 times
Wilford
1 year ago
B) collect logs
upvoted 0 times
...
Janella
1 year ago
A) verify the breadth of the attack
upvoted 0 times
...
...
Corinne
1 year ago
After that, we should scan hosts with updated signatures to ensure we have addressed all vulnerabilities.
upvoted 0 times
...
Jaleesa
1 year ago
I agree with Mattie. We also need to collect logs to understand the extent of the incident.
upvoted 0 times
...
Mattie
1 year ago
I think we should verify the breadth of the attack first.
upvoted 0 times
...

Save Cancel