Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 10 Question 101 Discussion

A SOC team receives multiple alerts by a rule that detects requests to malicious URLs and informs the incident response team to block the malicious URLs requested on the firewall. Which action will improve the effectiveness of the process?
B) Inform the user by enabling an automated email response when the rule is triggered. and D) Create an automation script for blocking URLs on the firewall when the rule is triggered.
A) Block local to remote HTTP/HTTPS requests on the firewall for users who triggered the rule.
C) Inform the incident response team by enabling an automated email response when the rule is triggered.

Cisco 350-201 Exam - Topic 10 Question 101 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 101
Topic #: 10
[All 350-201 Questions]

A SOC team receives multiple alerts by a rule that detects requests to malicious URLs and informs the incident response team to block the malicious URLs requested on the firewall. Which action will improve the effectiveness of the process?

Show Suggested Answer Hide Answer
Suggested Answer: B, D

Contribute your Thoughts:

0/2000 characters
Tijuana
9 months ago
Wait, can we really automate that? Sounds too good to be true!
upvoted 0 times
...
Joanne
9 months ago
Option C seems useful too, but D just makes more sense.
upvoted 0 times
...
Kerry
10 months ago
Not sure if blocking local to remote requests is a good idea.
upvoted 0 times
...
Carmela
10 months ago
Agree, D would save a lot of time.
upvoted 0 times
...
Rolande
10 months ago
I think option D is the best choice. Automation is key!
upvoted 0 times
...
Dannette
10 months ago
I think option B is less effective since just informing the user doesn't really stop the threat. We need a more proactive approach.
upvoted 0 times
...
Yasuko
11 months ago
I practiced a similar question where blocking requests directly was emphasized. So, option A seems like it could be effective too, but I'm not completely convinced.
upvoted 0 times
...
Tequila
11 months ago
I'm not entirely sure, but I feel like informing the incident response team automatically, like in option C, might help them respond faster.
upvoted 0 times
...
Kathryn
11 months ago
I remember discussing the importance of automation in incident response. I think option D could really streamline the process.
upvoted 0 times
...
Tiffiny
11 months ago
I'm a little confused by this question. It's not entirely clear to me what the best approach would be. I'm leaning towards option B, informing the user, but I'm not sure if that's the most effective solution. I'll need to re-read the question and the options carefully before making a decision.
upvoted 0 times
...
Christoper
11 months ago
Option D definitely seems like the way to go here. Automating the blocking of malicious URLs on the firewall when the rule is triggered is the most efficient solution. It will save the SOC team time and ensure a faster response to potential threats.
upvoted 0 times
...
Jose
11 months ago
Hmm, I'm a bit unsure about this one. I'm trying to decide between options C and D. Informing the incident response team automatically or creating an automation script to block the URLs. I'll need to think this through a bit more to decide which approach would be more effective.
upvoted 0 times
...
Chandra
11 months ago
This seems like a straightforward question about improving the effectiveness of a security process. I think I'll go with option D - creating an automation script to block the malicious URLs on the firewall when the rule is triggered. That should help streamline the process and reduce the manual effort required.
upvoted 0 times
...
Sue
1 year ago
Option A sounds like a good way to get everyone fired. Let's not block local traffic, folks. I'm with Adaline on this one - D is the winner.
upvoted 0 times
Mitzie
1 year ago
D) Create an automation script for blocking URLs on the firewall when the rule is triggered.
upvoted 0 times
...
Jesusa
1 year ago
A) Block local to remote HTTP/HTTPS requests on the firewall for users who triggered the rule.
upvoted 0 times
...
...
Della
1 year ago
Hmm, I'm not so sure about option B. Do we really want to clutter people's inboxes with automated emails? I'd prefer the automation script in option D.
upvoted 0 times
Francesco
1 year ago
Definitely, having an automation script in place will streamline the response process and prevent delays.
upvoted 0 times
...
Nidia
1 year ago
I agree, automation is key in these situations. It's more efficient than manual processes.
upvoted 0 times
...
Carri
1 year ago
Option D sounds like the best choice. It would save time and ensure the URLs are blocked quickly.
upvoted 0 times
...
...
Bea
1 year ago
Whoa, hold up! Option B might be a good idea too. Letting the user know when they've triggered the rule could help them avoid future issues.
upvoted 0 times
...
Mabel
1 year ago
I see both points, but I think option C is also important. Keeping the incident response team informed is crucial for coordination.
upvoted 0 times
...
Adaline
1 year ago
I think option D is the way to go. Automating the blocking process on the firewall is the most efficient solution here.
upvoted 0 times
Wava
1 year ago
I agree, creating a script to block URLs automatically is the most effective way to handle this situation.
upvoted 0 times
...
Lazaro
1 year ago
Option D is definitely the best choice. Automating the blocking process will save us a lot of time.
upvoted 0 times
...
...
Filiberto
1 year ago
I disagree, I believe option A is more effective. Blocking local to remote requests will prevent further damage.
upvoted 0 times
...
Adela
1 year ago
I think option D is the best choice. It will save time and ensure immediate action.
upvoted 0 times
...

Save Cancel