Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 5 Question 83 Discussion

Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)
A) Determine the type of data stored on the affected asset, document the access logs, and engage the incident response team. and D) Initiate a triage meeting with department leads to determine if the application is owned internally or used by any business unit and document the asset owner.
B) Identify who installed the application by reviewing the logs and gather a user access log from the HR department.
C) Verify user credentials on the affected asset, modify passwords, and confirm available patches and updates are installed.

Cisco 350-201 Exam - Topic 5 Question 83 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 83
Topic #: 5
[All 350-201 Questions]

Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A, D

Contribute your Thoughts:

0/2000 characters
Chun
9 months ago
I disagree, we should focus on the data type before anything else.
upvoted 0 times
...
Luisa
9 months ago
D is a good step, but we should also check the access logs first.
upvoted 0 times
...
Allene
10 months ago
Surprised there's an unknown app on the HR server! How did that happen?
upvoted 0 times
...
Jacob
10 months ago
I think identifying who installed it is crucial too.
upvoted 0 times
...
Trinidad
10 months ago
Definitely need to engage the incident response team!
upvoted 0 times
...
Lelia
10 months ago
I’m a bit confused about the steps, but I don’t think modifying passwords is relevant here. I feel like we should focus on documenting and investigating first, so A and D seem right.
upvoted 0 times
...
Gilma
11 months ago
I practiced a question like this where we had to determine ownership of an application. I think option D is crucial to figure out if anyone is using it.
upvoted 0 times
...
Lanie
11 months ago
I'm not entirely sure, but I feel like we might need to check the logs first to see who installed the app. Option B could be a good first step.
upvoted 0 times
...
An
11 months ago
I remember we discussed the importance of identifying the data type and involving the incident response team in similar scenarios. I think option A makes sense.
upvoted 0 times
...
Svetlana
11 months ago
Okay, I've got a plan. First, I'd verify the user credentials and make sure the system is patched and up-to-date. Then I'd document the asset owner and see if we can trace back who installed the application. That should give us a good starting point for the investigation.
upvoted 0 times
...
Luther
11 months ago
Hmm, I think the key here is to figure out if this application is actually being used by the organization. If it's not owned by any business unit, that's a red flag. I'd recommend initiating a triage meeting to get more context before taking any other actions.
upvoted 0 times
...
Oretha
11 months ago
I'm a bit unsure about this one. Should we try to identify who installed the application first, or focus on determining the data type and access logs? I'm not sure which approach would be more effective.
upvoted 0 times
...
Pedro
11 months ago
This seems like a straightforward incident response scenario. I'd start by documenting the details of the unknown application and its communication, then engage the incident response team to investigate further.
upvoted 0 times
...
Gladys
11 months ago
Okay, I know the Administration Server manages the domain configuration, so that's one for sure. Now I just need to figure out the other true statement.
upvoted 0 times
...
Tamesha
11 months ago
This one seems pretty straightforward. I'd go with A - accept the risk but monitor it closely.
upvoted 0 times
...
Octavio
11 months ago
I'm a little confused by this question. The options seem to cover a range of privacy-related topics, but I'm not sure which one specifically matches the Privacy Protection Act. I'll need to re-read the question and options a few times to try to figure this out.
upvoted 0 times
...
Freeman
11 months ago
This is a tricky one. I'm leaning towards the discounted forecast free cash flow approach, but I'll need to make sure I have all the necessary data and assumptions to do that calculation properly. Gotta be careful not to miss any key factors.
upvoted 0 times
...
Lawrence
2 years ago
I think verifying user credentials on the affected asset and confirming available patches are important steps too.
upvoted 0 times
...
Lavina
2 years ago
I believe we should also initiate a triage meeting with department leads to determine the asset owner.
upvoted 0 times
...
Louisa
2 years ago
I agree with Nan. We need to act fast and document the access logs as well.
upvoted 0 times
...
Nan
2 years ago
I think the next step should be to determine the type of data stored on the affected asset and engage the incident response team.
upvoted 0 times
...
Omega
2 years ago
That's a good point, Justine. By doing that, they can verify user credentials on the affected asset and confirm available patches and updates are installed.
upvoted 0 times
...
Justine
2 years ago
But shouldn't they first identify who installed the application? I think they should gather a user access log from the HR department.
upvoted 0 times
...
Justine
2 years ago
I agree with Omega. They should also initiate a triage meeting with department leads to document the asset owner.
upvoted 0 times
...
Omega
2 years ago
I think the engineers should determine the type of data stored on the affected asset and engage the incident response team.
upvoted 0 times
...
Troy
2 years ago
Engaging the incident response team is also a must. They'll have the expertise to properly investigate and handle this situation.
upvoted 0 times
...
Linette
2 years ago
My first thought is that we should definitely determine the type of data stored on the affected asset. That could be crucial in understanding the potential impact.
upvoted 0 times
Cordelia
2 years ago
C) Verify user credentials on the affected asset, modify passwords, and confirm available patches and updates are installed.
upvoted 0 times
...
Dortha
2 years ago
A) Determine the type of data stored on the affected asset, document the access logs, and engage the incident response team.
upvoted 0 times
...
...
Melissa
2 years ago
I agree, this is a serious security concern. We need to act quickly to identify the threat and mitigate the risk.
upvoted 0 times
...
Lashon
2 years ago
This is a tricky question. We need to figure out the best way to handle this unknown application that's communicating with external addresses without encryption.
upvoted 0 times
...

Save Cancel