Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-740 Exam - Topic 1 Question 15 Discussion

A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the machine is infected by trojan malware. What must the analyst do to mitigate the threat using Cisco Secure Endpoint?
D) Start isolation of the machine on the Computers tab
A) Identify the malicious IPs and place them in a blocked list
B) Create an IP Block list and add the IP address of the affected endpoint
C) Enable scheduled scans to detect and block the executable files

Cisco 300-740 Exam - Topic 1 Question 15 Discussion

Actual exam question for Cisco's 300-740 exam
Question #: 15
Topic #: 1
[All 300-740 Questions]

A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the machine is infected by trojan malware. What must the analyst do to mitigate the threat using Cisco Secure Endpoint?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Kristine
3 days ago
Blocking the IPs is important, but…
upvoted 0 times
...
Estrella
8 days ago
C could help later, but not immediate.
upvoted 0 times
...
Miesha
13 days ago
I agree with Silvana, D is crucial.
upvoted 0 times
...
Ula
19 days ago
A is good too, but not enough.
upvoted 0 times
...
Silvana
24 days ago
It prevents further damage.
upvoted 0 times
...
Kristine
29 days ago
Why isolation?
upvoted 0 times
...
Silvana
1 month ago
I think D is the best choice.
upvoted 0 times
...
Kristine
1 month ago
This scenario is tricky.
upvoted 0 times
...
Dalene
1 month ago
I disagree, the IP block list won't help if the malware is already on the machine.
upvoted 0 times
...
Veda
2 months ago
Wait, how did they even download a file named that? Sounds sketchy.
upvoted 0 times
...
Jeannetta
2 months ago
Scheduled scans are good, but isolation should come first.
upvoted 0 times
...
Albina
2 months ago
I think blocking the malicious IPs is a must too.
upvoted 0 times
...
Miles
2 months ago
Definitely need to isolate that machine ASAP!
upvoted 0 times
...
Oren
2 months ago
I vaguely recall something about creating IP block lists, but I wonder if that’s more of a long-term solution. Could option B be relevant?
upvoted 0 times
...
Kristal
4 months ago
I practiced a similar question where we had to deal with malware. I think enabling scheduled scans is useful, but it might not be the immediate step needed here.
upvoted 0 times
...
Jerry
4 months ago
I'm not entirely sure, but I feel like blocking the malicious IPs could help too. Maybe option A?
upvoted 0 times
...
Leslie
4 months ago
I remember we discussed the importance of isolating infected machines to prevent further spread. I think option D might be the right choice.
upvoted 0 times
...

Save Cancel