Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 5 Question 18 Discussion

Refer to the exhibit.An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?
A) Exclude the step ''BAN malicious IP'' to allow analysts to conduct and track the remediation
B) Include a step ''Take a Snapshot'' to capture the endpoint state to contain the threat for analysis
C) Exclude the step ''Check for GeoIP location'' to allow analysts to analyze the location and the associated risk based on asset criticality
D) Include a step ''Reporting'' to alert the security department of threats identified by the SOAR reporting engine

Cisco 350-201 Exam - Topic 5 Question 18 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 18
Topic #: 5
[All 350-201 Questions]

Refer to the exhibit.

An engineer configured this SOAR solution workflow to identify account theft threats and privilege escalation, evaluate risk, and respond by resolving the threat. This solution is handling more threats than Security analysts have time to analyze. Without this analysis, the team cannot be proactive and anticipate attacks. Which action will accomplish this goal?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Kip
10 months ago
Reporting is important, but we need to analyze first!
upvoted 0 times
...
Viva
10 months ago
Wait, why would we exclude any steps? Sounds counterproductive.
upvoted 0 times
...
Ligia
11 months ago
Not sure about excluding the GeoIP check, that seems risky.
upvoted 0 times
...
Ma
11 months ago
Totally agree, capturing the endpoint state is crucial!
upvoted 0 times
...
Marta
11 months ago
I think option B is the best choice for analysis.
upvoted 0 times
...
Pamella
11 months ago
Okay, I think I've got this. The Spam Quarantine End-User Authentication Query is the setting that validates end-users via LDAP during login to the End-User Quarantine. I'm confident that's the right answer.
upvoted 0 times
...
Edison
11 months ago
This question seems straightforward, but I want to make sure I understand the requirements correctly. I'll need to review the details carefully before answering.
upvoted 0 times
...

Save Cancel