Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 10 Question 111 Discussion

Refer to the exhibit.An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
A) Exclude the step ''BAN malicious IP'' to allow analysts to conduct and track the remediation
B) Include a step ''Take a Snapshot'' to capture the endpoint state to contain the threat for analysis
C) Exclude the step ''Check for GeoIP location'' to allow analysts to analyze the location and the associated risk based on asset criticality
D) Include a step ''Reporting'' to alert the security department of threats identified by the SOAR reporting engine

Cisco 350-201 Exam - Topic 10 Question 111 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 111
Topic #: 10
[All 350-201 Questions]

Refer to the exhibit.

An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Arthur
9 months ago
Wow, I didn't realize how many threats they were handling!
upvoted 0 times
...
Lasandra
9 months ago
I think "Take a Snapshot" is a smart move!
upvoted 0 times
...
Shonda
9 months ago
"Reporting" is definitely needed for better visibility.
upvoted 0 times
...
Carma
9 months ago
Not sure if "Check for GeoIP location" should be excluded.
upvoted 0 times
...
Elly
9 months ago
Excluding "BAN malicious IP" seems risky.
upvoted 0 times
...
Hana
10 months ago
I studied that excluding steps can sometimes lead to missing important context, so maybe "Check for GeoIP location" shouldn't be excluded.
upvoted 0 times
...
Avery
10 months ago
I feel like "Reporting" could be crucial for alerting the team, but I'm not confident if it's the best choice here.
upvoted 0 times
...
Colene
10 months ago
I remember a practice question where we had to prioritize threat analysis, and I think excluding certain steps might actually hinder that process.
upvoted 0 times
...
Joesph
10 months ago
I'm not entirely sure, but I think including a "Take a Snapshot" step could help with analyzing the threat later on.
upvoted 0 times
...
Afton
11 months ago
I'm feeling pretty confident about this one. The key is to remove any steps that are automating the threat response, so that the analysts can actually analyze the threats and anticipate future attacks. I think the "Exclude the step 'BAN malicious IP'" option is the best choice here.
upvoted 0 times
...
Myra
11 months ago
Okay, I think I've got it. The goal is to make the security analysts more proactive, so we need to find a way to give them more visibility and control over the threat analysis process. I'm leaning towards the "Take a Snapshot" option, as that could help them better understand the threats.
upvoted 0 times
...
Merlyn
11 months ago
Hmm, I'm a bit confused by the different options. I think I need to re-read the question and the exhibit carefully to make sure I understand the goal and the potential actions.
upvoted 0 times
...
Melissa
11 months ago
This looks like a tricky question. I'm not sure if I fully understand the SOAR solution workflow, but I think the key is to find a way to allow the security analysts to analyze the threats more effectively.
upvoted 0 times
...

Save Cancel