Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 8 Question 79 Discussion

A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?
B) Disable affected assets and isolate them for further investigation. and D) Configure affected devices to disable the Finger service.
A) Disable BIND forwarding from the DNS server to avoid reconnaissance.
C) Configure affected devices to disable NETRJS protocol.

Cisco 350-201 Exam - Topic 8 Question 79 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 79
Topic #: 8
[All 350-201 Questions]

A SOC team is investigating a recent, targeted social engineering attack on multiple employees. Cross- correlated log analysis revealed that two hours before the attack, multiple assets received requests on TCP port 79. Which action should be taken by the SOC team to mitigate this attack?

Show Suggested Answer Hide Answer
Suggested Answer: B, D

Contribute your Thoughts:

0/2000 characters
Kaycee
9 months ago
Wait, disabling BIND forwarding? That seems off.
upvoted 0 times
...
Hermila
10 months ago
Isolating assets sounds like a solid move.
upvoted 0 times
...
Elke
10 months ago
Not sure if that's enough, though.
upvoted 0 times
...
Margot
10 months ago
Definitely should disable that service!
upvoted 0 times
...
Katie
10 months ago
TCP port 79 is for Finger service, right?
upvoted 0 times
...
Evangelina
10 months ago
Disabling BIND forwarding sounds familiar, but I feel like that’s more about DNS issues rather than directly mitigating this social engineering attack.
upvoted 0 times
...
Rikki
11 months ago
I think we practiced a similar question where disabling certain services was the right move, but I can't recall if it was specifically about NETRJS or Finger.
upvoted 0 times
...
Macy
11 months ago
I'm not entirely sure, but isolating the affected assets seems like a good first step to prevent further damage.
upvoted 0 times
...
Janna
11 months ago
I remember studying about TCP port 79 being associated with the Finger service, so maybe disabling that could help.
upvoted 0 times
...
Gladys
11 months ago
I think I've got this one. The key is that the attack was targeted, and the logs show activity on port 79 beforehand. Disabling the Finger service on the affected devices seems like the most direct way to address the reconnaissance aspect of the attack.
upvoted 0 times
...
Jina
11 months ago
I'm a bit confused by this one. The Finger service on port 79 - is that really the best way to mitigate a social engineering attack? I'm not sure that's the right approach here.
upvoted 0 times
...
Marvel
11 months ago
Okay, let's see. The question is asking about mitigating a social engineering attack, and the clue is that there were requests on TCP port 79 before the attack. I'm pretty sure that's the Finger service, so I'd go with option D.
upvoted 0 times
...
King
11 months ago
Hmm, this seems like a tricky one. I'll need to think carefully about the implications of each option.
upvoted 0 times
...
Adelina
11 months ago
Wait, do I need to specify the namespace when creating the pod? I'm a little unsure about that part.
upvoted 0 times
...
Shoshana
11 months ago
Whew, this is a lot to take in! I'm a bit overwhelmed by all the different components and interactions. I'll need to really focus and make sure I understand the core problems before I start proposing solutions. Maybe I'll jot down some notes first to organize my thoughts.
upvoted 0 times
...
Vannessa
1 year ago
Fingers crossed the answer is D! I can't imagine anyone actually using the Finger service these days, it's gotta be a relic from the 80s.
upvoted 0 times
Allene
1 year ago
Let's go ahead and configure the affected devices to disable the Finger service.
upvoted 0 times
...
Lorrie
1 year ago
Disabling the Finger service sounds like a good plan to mitigate the attack.
upvoted 0 times
...
Sheldon
1 year ago
I think we should disable the Finger service on the affected devices.
upvoted 0 times
...
Paola
1 year ago
I agree, the Finger service is definitely outdated.
upvoted 0 times
...
...
Armando
1 year ago
Wait, is the Finger service actually a real thing? I thought that was just a joke from The IT Crowd! Either way, better disable it just in case.
upvoted 0 times
Jade
1 year ago
Agreed, let's take action and configure the devices to disable the Finger service.
upvoted 0 times
...
Carlota
1 year ago
We should definitely disable it on the affected devices to prevent further attacks.
upvoted 0 times
...
Joye
1 year ago
Yes, the Finger service is real and can be exploited by attackers.
upvoted 0 times
...
...
Janessa
1 year ago
Disabling BIND forwarding could work, but that feels like a bandaid solution. Isolating the affected assets seems like the most thorough approach to me.
upvoted 0 times
Marylin
1 year ago
C: We should also consider configuring devices to disable the Finger service to prevent future attacks.
upvoted 0 times
...
Hyun
1 year ago
B: I agree, but isolating the affected assets for further investigation might be more effective.
upvoted 0 times
...
Erick
1 year ago
A: I think disabling BIND forwarding could help stop the attack.
upvoted 0 times
...
...
Ula
1 year ago
But wouldn't it be better to isolate the affected assets for further investigation?
upvoted 0 times
...
Chery
1 year ago
I agree with Charlesetta, it will help prevent further reconnaissance.
upvoted 0 times
...
Charlesetta
1 year ago
I think we should disable BIND forwarding from the DNS server.
upvoted 0 times
...
Kelvin
1 year ago
Hmm, I'm not sure disabling NETRJS is the right move here. Wouldn't that just bring more attention to the issue? I'd go with option D to be safe.
upvoted 0 times
In
1 year ago
Yeah, I think that would be a good choice to mitigate the attack.
upvoted 0 times
...
Krystina
1 year ago
I agree, disabling the Finger service seems like a safer option.
upvoted 0 times
...
Kindra
1 year ago
Yeah, I think that would be a good choice to mitigate the attack.
upvoted 0 times
...
Wilda
1 year ago
I agree, disabling the Finger service seems like a safer option.
upvoted 0 times
...
...
Therese
1 year ago
But what about isolating the affected assets for investigation?
upvoted 0 times
...
Kimbery
1 year ago
The Finger service sounds like a very suspicious protocol. Disabling it seems like the best way to address this attack!
upvoted 0 times
Geoffrey
1 year ago
We should also configure affected devices to disable the NETRJS protocol.
upvoted 0 times
...
Ivette
1 year ago
Yes, isolating them would help prevent further damage.
upvoted 0 times
...
Elfriede
1 year ago
But should we also isolate the affected assets for further investigation?
upvoted 0 times
...
My
1 year ago
I agree, disabling the Finger service is a good idea.
upvoted 0 times
...
...
Karina
1 year ago
I agree with Ryann, it will help prevent further reconnaissance.
upvoted 0 times
...
Ryann
1 year ago
I think we should disable BIND forwarding from the DNS server.
upvoted 0 times
...

Save Cancel