Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 6 Question 52 Discussion

After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?
C) Inspect registry entries for recently executed files.
A) Analyze the applications and services running on the affected workstation.
B) Compare workstation configuration and asset configuration policy to identify gaps.
D) Review audit logs for privilege escalation events.

Cisco 350-201 Exam - Topic 6 Question 52 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 52
Topic #: 6
[All 350-201 Questions]

After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
King
10 months ago
I disagree, the applications are where the malware usually hides.
upvoted 0 times
...
My
10 months ago
Gaps in configuration can lead to breaches, so that’s important too.
upvoted 0 times
...
Tonette
10 months ago
Surprised no one mentioned inspecting registry entries!
upvoted 0 times
...
Olen
11 months ago
I think checking the audit logs is more critical.
upvoted 0 times
...
Polly
11 months ago
Definitely should analyze the applications first.
upvoted 0 times
...
Angella
11 months ago
Comparing the workstation configuration to the asset policy could help identify gaps, but I wonder if we should focus more on immediate evidence first.
upvoted 0 times
...
Laine
11 months ago
Reviewing audit logs for privilege escalation events sounds relevant, but I feel like we should first look at the applications. It's hard to decide.
upvoted 0 times
...
Roosevelt
11 months ago
I'm not entirely sure, but I remember something about checking registry entries for recently executed files being important in similar practice questions.
upvoted 0 times
...
Karima
11 months ago
I think the next step might be to analyze the applications and services running on the workstation. That seems like a logical way to start identifying what went wrong.
upvoted 0 times
...
Tori
11 months ago
Hmm, I'm a bit unsure about this one. I'm not sure if the compatibility of virus scanners or the organization's firewall are really relevant when evaluating the cloud provider's security. I'll have to think this through carefully.
upvoted 0 times
...

Save Cancel