Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 6 Question 130 Discussion

A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?
B) Analyze event logs and restrict network access
A) Determine the systems involved and deploy available patches
C) Review access lists and require users to increase password complexity
D) Identify the attack vector and update the IDS signature list

Cisco 350-201 Exam - Topic 6 Question 130 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 130
Topic #: 6
[All 350-201 Questions]

A threat actor used a phishing email to deliver a file with an embedded macro. The file was opened, and a remote code execution attack occurred in a company's infrastructure. Which steps should an engineer take at the recovery stage?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Audra
4 days ago
Definitely need to analyze event logs first.
upvoted 0 times
...
Karma
9 days ago
I recall that increasing password complexity is generally good, but I'm not sure if it directly relates to recovery from this type of attack. Option C feels a bit off to me.
upvoted 0 times
...
Marshall
14 days ago
I think we practiced a similar question where we had to determine the systems involved first. So, option A seems like a logical step to take.
upvoted 0 times
...
Stephanie
19 days ago
I'm a bit unsure about the recovery steps, but I feel like identifying the attack vector is important. Maybe option D is the right choice?
upvoted 0 times
...
Rodney
24 days ago
I remember we discussed the importance of analyzing event logs in our last practice session, so I think option B might be crucial here.
upvoted 0 times
...

Save Cancel