Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 6 Question 89 Discussion

The network operations center has identified malware, created a ticket within their ticketing system, and assigned the case to the SOC with high-level information. A SOC analyst was able to stop the malware from spreading and identified the attacking host. What is the next step in the incident response workflow?
A) eradication and recovery
B) post-incident activity
C) containment
D) detection and analysis

Cisco 350-201 Exam - Topic 6 Question 89 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 89
Topic #: 6
[All 350-201 Questions]

The network operations center has identified malware, created a ticket within their ticketing system, and assigned the case to the SOC with high-level information. A SOC analyst was able to stop the malware from spreading and identified the attacking host. What is the next step in the incident response workflow?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Clay
9 months ago
Just stopping the malware isn’t enough, right?
upvoted 0 times
...
Lillian
9 months ago
Wait, are we sure containment isn't the priority here?
upvoted 0 times
...
Alexia
10 months ago
Totally agree with eradication, that’s crucial!
upvoted 0 times
...
Cristen
10 months ago
I think containment comes first, though.
upvoted 0 times
...
Ivette
10 months ago
Next step is definitely eradication and recovery!
upvoted 0 times
...
Oliva
10 months ago
I’m a bit confused; I thought post-incident activity came later in the process. But maybe it’s important to document everything before moving on?
upvoted 0 times
...
Gilma
11 months ago
I feel like we did a practice question where containment was emphasized as the immediate action after stopping the spread. Could that be the right answer?
upvoted 0 times
...
Tu
11 months ago
I think we might need to focus on eradication and recovery next, especially since the malware was stopped. That seems like a logical progression.
upvoted 0 times
...
Oliva
11 months ago
I remember we talked about containment being crucial right after identifying the threat, but I'm not entirely sure if that's the next step here.
upvoted 0 times
...
Sunshine
11 months ago
I'm a bit confused here. Is post-incident activity the right choice, since the malware has already been detected and stopped? Or is there a specific containment process I'm missing? I'll have to review the incident response workflow again.
upvoted 0 times
...
Mabelle
11 months ago
Containment makes the most sense to me. We need to isolate the affected systems and prevent any further damage before we can move on to eradication and recovery. I feel good about this one.
upvoted 0 times
...
Jade
11 months ago
Okay, let's think this through. The malware has been detected and the attacking host has been identified, so the next logical step would be to contain the threat. I'm pretty confident that's the right answer.
upvoted 0 times
...
Torie
11 months ago
I'm a little unsure about this one. Is it eradication and recovery, since the malware has already been identified and stopped from spreading? Or is there something else I'm missing?
upvoted 0 times
...
Zachary
11 months ago
Hmm, this seems like a straightforward incident response question. I think the next step would be containment, to prevent the malware from spreading further.
upvoted 0 times
...
Carli
11 months ago
Hmm, I'm a bit unsure about this one. I'll need to think through the different options and how they might work in practice for inducting new staff. Hopefully, I can eliminate a couple of the choices.
upvoted 0 times
...
Dewitt
11 months ago
I think it might be A and D, but I'm not completely sure about C.
upvoted 0 times
...
Ashley
2 years ago
I'd love to see the look on the malware's face when we hit it with the containment hammer. Bet it'll be crying 'Uncle!'.
upvoted 0 times
...
Elke
2 years ago
Containment is the way to go. Gotta contain that threat before we can move on to the fun part – eradicating it!
upvoted 0 times
Annett
2 years ago
B) post-incident activity
upvoted 0 times
...
Donte
2 years ago
Let's focus on containing the threat first.
upvoted 0 times
...
Tabetha
2 years ago
C) containment
upvoted 0 times
...
Lindsey
2 years ago
A) eradication and recovery
upvoted 0 times
...
...
Hannah
2 years ago
Detection and analysis? Nah, we already did that. Now it's time to put the smackdown on that malware!
upvoted 0 times
...
Gail
2 years ago
Containment all the way! Can't let that nasty bug infect the whole network. Time to quarantine the host!
upvoted 0 times
Karima
2 years ago
What is the next step in the incident response workflow?
upvoted 0 times
...
Catarina
2 years ago
What is the next step in the incident response workflow?
upvoted 0 times
...
...
Aja
2 years ago
Wait, isn't eradication and recovery the logical next step? Gotta get rid of that malware and restore everything to normal.
upvoted 0 times
Sue
2 years ago
B) post-incident activity
upvoted 0 times
...
Deandrea
2 years ago
C) containment
upvoted 0 times
...
Paris
2 years ago
A) eradication and recovery
upvoted 0 times
...
...
Lorrine
2 years ago
Hmm, I'd say post-incident activity. Gotta make sure we learn from this and prevent it from happening again.
upvoted 0 times
Eun
2 years ago
C) containment
upvoted 0 times
...
Delsie
2 years ago
B) post-incident activity
upvoted 0 times
...
Gilberto
2 years ago
A) eradication and recovery
upvoted 0 times
...
...
Martina
2 years ago
I agree with Nidia, containing the malware should be the priority.
upvoted 0 times
...
Nidia
2 years ago
I think the next step is containment.
upvoted 0 times
...
Sherron
2 years ago
Containment is definitely the next step. Can't let that malware spread any further!
upvoted 0 times
Clarinda
2 years ago
After containment, we can focus on eradicating the malware and recovering any affected systems.
upvoted 0 times
...
Martina
2 years ago
Yes, containment is crucial to prevent further damage.
upvoted 0 times
...
Linsey
2 years ago
After containment, we can focus on eradicating the malware and recovering any affected systems.
upvoted 0 times
...
Zita
2 years ago
After containment, we can focus on eradicating the malware and recovering any affected systems.
upvoted 0 times
...
Stephen
2 years ago
Yes, containment is crucial to prevent further damage.
upvoted 0 times
...
Mickie
2 years ago
Yes, containment is crucial to prevent further damage.
upvoted 0 times
...
...

Save Cancel