Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 8 Question 71 Discussion

A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while traveling. The attacker has the user's credentials and is attempting to connect to the network.What is the next step in handling the incident?
A) Block the source IP from the firewall
B) Perform an antivirus scan on the laptop
C) Identify systems or services at risk
D) Identify lateral movement

Cisco 350-201 Exam - Topic 8 Question 71 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 71
Topic #: 8
[All 350-201 Questions]

A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while traveling. The attacker has the user's credentials and is attempting to connect to the network.

What is the next step in handling the incident?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Ezekiel
9 months ago
Wait, how did the attacker get the user's credentials in the first place?
upvoted 0 times
...
Shayne
10 months ago
Agree, but we should also check for other compromised accounts.
upvoted 0 times
...
Denny
10 months ago
A scan on the laptop might not be enough, though.
upvoted 0 times
...
Staci
10 months ago
I think identifying lateral movement is crucial here.
upvoted 0 times
...
Penney
10 months ago
Definitely need to block that source IP ASAP.
upvoted 0 times
...
Leah
11 months ago
I recall that identifying systems or services at risk is essential, especially if the attacker has credentials. It seems like a logical next step to assess the overall impact.
upvoted 0 times
...
Helaine
11 months ago
I feel like performing an antivirus scan on the laptop is necessary, but it might not be the immediate priority if the attacker is still active.
upvoted 0 times
...
Claribel
11 months ago
I think identifying lateral movement could be crucial since the attacker might try to access other systems. It feels similar to a practice question we did on incident response.
upvoted 0 times
...
Lynette
11 months ago
I remember we discussed the importance of blocking the source IP to prevent further access, but I'm not sure if that's the best first step here.
upvoted 0 times
...
Leontine
11 months ago
I'm a bit confused by this question. I'm not sure what all the different technologies and features are for the ES3000 V3. I'll have to make an educated guess and hope for the best.
upvoted 0 times
...
Micah
11 months ago
I'm confident I can figure this out. Let me review the options and think through the requirements.
upvoted 0 times
...
Curtis
11 months ago
I want to say that qualitative aspects are actually significant in our assessments, though I can't recall if option C is directly relevant.
upvoted 0 times
...
Lorriane
11 months ago
I'm leaning towards option C. The providers are collectively restricting how they'll do business, which sounds like a group boycott. And the market division is clear in the second scenario.
upvoted 0 times
...
Lonna
11 months ago
Option D seems like the right choice to me. High impact risks that may arise occasionally should be the top priority.
upvoted 0 times
...
Youlanda
1 year ago
C is the way to go! Gotta catch 'em all, like a cybersecurity Pokemon master!
upvoted 0 times
Clorinda
1 year ago
D) Identify lateral movement
upvoted 0 times
...
Goldie
1 year ago
A) Block the source IP from the firewall
upvoted 0 times
...
Cary
1 year ago
C) Identify systems or services at risk
upvoted 0 times
...
...
Skye
1 year ago
I agree with C. This will help the incident response team understand the full scope of the attack and take appropriate measures to mitigate the risk.
upvoted 0 times
Johnna
1 year ago
C) Identify systems or services at risk
upvoted 0 times
...
Carman
1 year ago
B) Perform an antivirus scan on the laptop
upvoted 0 times
...
Lauran
1 year ago
A) Block the source IP from the firewall
upvoted 0 times
...
...
Alesia
1 year ago
Definitely C. Blocking the source IP is a temporary fix, and an antivirus scan may not catch everything. Identifying the affected systems and potential lateral movement is key to resolving this incident.
upvoted 0 times
Shay
1 year ago
D) Identify lateral movement
upvoted 0 times
...
Glendora
1 year ago
C) Identify systems or services at risk
upvoted 0 times
...
Rodolfo
1 year ago
A) Block the source IP from the firewall
upvoted 0 times
...
Yvonne
1 year ago
D) Identify lateral movement
upvoted 0 times
...
Chantell
1 year ago
C) Identify systems or services at risk
upvoted 0 times
...
Barrett
1 year ago
A) Block the source IP from the firewall
upvoted 0 times
...
...
Dominque
1 year ago
Hmm, I would say C is the next step. Identifying the systems or services at risk is crucial to contain the incident and prevent further damage.
upvoted 0 times
...
Dick
1 year ago
After that, we should block the source IP from the firewall to prevent further access.
upvoted 0 times
...
Mammie
1 year ago
I agree with Laquita, understanding the potential impact is crucial.
upvoted 0 times
...
Laquita
1 year ago
We should identify systems or services at risk first.
upvoted 0 times
...
Franklyn
1 year ago
After that, we can block the source IP from the firewall to prevent further access.
upvoted 0 times
...
Svetlana
1 year ago
I agree with Corazon, we need to know what's at risk before taking any action.
upvoted 0 times
...
Corazon
1 year ago
We should identify systems or services at risk first.
upvoted 0 times
...

Save Cancel