Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 4 Question 85 Discussion

A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which two elements are part of the eradication phase for this incident? (Choose two.)
A) anti-malware software
B) data and workload isolation
C) centralized user management
D) intrusion prevention system
E) enterprise block listing solution

Cisco 300-215 Exam - Topic 4 Question 85 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 85
Topic #: 4
[All 300-215 Questions]

A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which two elements are part of the eradication phase for this incident? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Ira
9 months ago
Not sure about enterprise block listing being effective in this case.
upvoted 0 times
...
Novella
9 months ago
Agree, anti-malware is a must for eradication!
upvoted 0 times
...
Lenita
10 months ago
Surprised that centralized user management isn't included here.
upvoted 0 times
...
Hannah
10 months ago
I think intrusion prevention should be part of it too!
upvoted 0 times
...
Lewis
10 months ago
Definitely anti-malware software and data isolation.
upvoted 0 times
...
Rebecka
10 months ago
I’m leaning towards enterprise block listing as a way to prevent future connections, but I’m not entirely sure if it fits the eradication phase specifically.
upvoted 0 times
...
Barney
11 months ago
I practiced a similar question, and I feel like an intrusion prevention system might be more about detection than eradication.
upvoted 0 times
...
Linn
11 months ago
I think data and workload isolation is definitely part of the eradication phase. It makes sense to contain the threat before removing it.
upvoted 0 times
...
Long
11 months ago
I remember that the eradication phase is about removing the threat, but I'm not sure if anti-malware software is the best choice here.
upvoted 0 times
...
Howard
11 months ago
Enterprise block listing solution seems like it could be part of the eradication process too. Blocking the unidentified senders might help stop the connection attempts.
upvoted 0 times
...
Dalene
11 months ago
Okay, I've got a strategy. The eradication phase is about removing the threat, so I'll look for options that directly address the issue, like anti-malware software and intrusion prevention.
upvoted 0 times
...
Marion
11 months ago
Hmm, I'm a bit unsure about this one. The incident response playbook is mentioned, but I'm not totally clear on what the eradication phase entails. I'll have to think this through carefully.
upvoted 0 times
...
Fannie
11 months ago
This question seems straightforward. I'll focus on the "eradication phase" part and think about what that might involve.
upvoted 0 times
...
Teddy
11 months ago
Data and workload isolation seems like a good choice for eradication. Separating the affected systems from the rest of the network could help contain the issue. I'll mark that one down.
upvoted 0 times
...
Nidia
1 year ago
I bet the security team is wishing they had a solid firewall in place to block those TCP/135 connection attempts. Guess they'll have to settle for an IPS instead. *chuckles*
upvoted 0 times
Ruby
1 year ago
C: Hopefully they can isolate the data and workload to prevent any further attacks.
upvoted 0 times
...
An
1 year ago
B: Yeah, an IPS will have to do the job for now.
upvoted 0 times
...
Elliot
1 year ago
A: They definitely need a strong firewall to block those connection attempts.
upvoted 0 times
...
...
Martina
1 year ago
B and D, no doubt! Gotta isolate that infected data and use the IPS to block those pesky TCP/135 connection attempts. Easy peasy, lemon squeezy!
upvoted 0 times
...
Richelle
1 year ago
Hmm, this is a tricky one. I'm leaning towards B and D, but I'm also wondering if C might be relevant for the eradication phase. I'll have to think this through a bit more.
upvoted 0 times
...
Elza
1 year ago
I'm not sure about this one. I was thinking A and E might be the right answers, but I'm not confident. Guess I need to review my incident response playbook again.
upvoted 0 times
Delpha
1 year ago
You got it! Those are the two elements for the eradication phase.
upvoted 0 times
...
Matt
1 year ago
E) enterprise block listing solution
upvoted 0 times
...
Hyman
1 year ago
B) data and workload isolation
upvoted 0 times
...
Rosina
1 year ago
Those are the correct choices for the eradication phase. Good job!
upvoted 0 times
...
Cordie
1 year ago
D) intrusion prevention system
upvoted 0 times
...
Genevive
1 year ago
A) anti-malware software
upvoted 0 times
...
...
Leontine
1 year ago
I think the answer is B and D. Isolating the affected data and systems, and using an IPS to detect and prevent further intrusions sound like the right steps for the eradication phase.
upvoted 0 times
Tawny
1 year ago
It's important to follow the incident response playbook to ensure a thorough eradication process.
upvoted 0 times
...
Doyle
1 year ago
Using an IPS to detect and prevent further intrusions is also important to stop the attack.
upvoted 0 times
...
Kenneth
1 year ago
I agree, isolating the affected data and systems is crucial in the eradication phase.
upvoted 0 times
...
...
Dwight
1 year ago
I believe data and workload isolation is also crucial in the eradication phase to contain the threat.
upvoted 0 times
...
Barb
1 year ago
I agree with Rozella. We should also consider using intrusion prevention system for eradication.
upvoted 0 times
...
Rozella
1 year ago
I think we should use anti-malware software to eradicate the threat.
upvoted 0 times
...

Save Cancel