exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 37 discussion

Actual exam question from Cisco's 350-201
Question #: 37
Topic #: 1
[All 350-201 Questions]

An engineer received an alert of a zero-day vulnerability affecting desktop phones through which an attacker sends a crafted packet to a device, resets the credentials, makes the device unavailable, and allows a default administrator account login. Which step should an engineer take after receiving this alert?

  • A. Initiate a triage meeting to acknowledge the vulnerability and its potential impact
  • B. Determine company usage of the affected products
  • C. Search for a patch to install from the vendor
  • D. Implement restrictions within the VoIP VLANS
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CiscoTester
Highly Voted 1 year, 11 months ago
It doesn't mention any incidents, an alert could be the vendors 0day advisory. If there was an incident A,C,D would all be correct because it doesn't specify a IR phase. This time I will choose B
upvoted 7 times
...
marceus
Most Recent 2 months, 3 weeks ago
Selected Answer: B
ChatGPT: In summary, determining usage helps prioritize the vulnerability's impact in the context of your organization, and it's the best first step to take after receiving the alert.
upvoted 1 times
...
DrVoIP
8 months, 3 weeks ago
D. Implement restrictions within the VoIP VLANS After receiving an alert about a zero-day vulnerability affecting desktop phones, the engineer should immediately take action to mitigate the threat. One of the first steps in this process should be to implement restrictions within the VoIP VLANs to prevent unauthorized access and limit the scope of the attack. This could involve measures such as updating firewall rules, configuring access control lists, or isolating affected devices from the network until a patch can be applied. The engineer should also continue to monitor the situation and work with the vendor to identify and implement a patch as soon as possible. - ChatGPT
upvoted 1 times
...
Noxman
9 months, 3 weeks ago
Selected Answer: B
zero-day vulnerability have no patches yet, check if company is using affected products
upvoted 1 times
...
kyle942
10 months ago
Selected Answer: B
Cisco playbook graph shows the floww: https://www.cisco.com/c/dam/en_us/about/security/images/csc_child_pages/white_papers/risk-triage-sir-flowchart.gif
upvoted 1 times
...
Medjai89
10 months, 3 weeks ago
A. https://handbook.sourcegraph.com/departments/security/vulnerability-management-process/
upvoted 2 times
Medjai89
10 months, 2 weeks ago
Its B. First step from cisco is to ask if the product is used in the environment
upvoted 1 times
...
...
Medjai89
11 months, 1 week ago
Guys, did any1 passed the exam ?
upvoted 3 times
...
kyle942
1 year ago
Selected Answer: A
https://tools.cisco.com/security/center/resources/vulnerability_risk_triage.html#3
upvoted 1 times
kyle942
1 year ago
Running affected product? Does the organization use the affected product in its environment?
upvoted 1 times
...
...
TOLU1985
1 year, 1 month ago
Selected Answer: A
A best fits
upvoted 1 times
...
Bobster02
2 years ago
Agree - first step always is correct identification of the problem.
upvoted 1 times
...
rhaphaexzzux
2 years ago
A - Identification: Once a security breach has been detected, as much information as possible must be collected about it. What flaw did it exploit? What was its objective? Is it continuing to spread? Collect all the data provided by security tools and analyze it.
upvoted 1 times
...
kou
2 years, 2 months ago
I think D is the correct answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago