exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 117 discussion

Actual exam question from Cisco's 350-201
Question #: 117
Topic #: 1
[All 350-201 Questions]

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

  • A. Disconnect the affected server from the network.
  • B. Analyze the source.
  • C. Access the affected server to confirm compromised files are encrypted.
  • D. Determine the attack surface.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TrainingTeam
6 months, 2 weeks ago
Selected Answer: A
When an intrusion event is detected and personal data has been accessed, the immediate action to contain the attack is to disconnect the affected server from the network. This prevents the attacker from accessing more resources or causing further damage and allows the organization to begin the process of investigating and eradicating the threat
upvoted 1 times
...
Alizade
1 year, 4 months ago
Selected Answer: A
A. Disconnect the affected server from the network.
upvoted 1 times
...
DrVoIP
2 years, 2 months ago
The first action that must be taken to contain this attack is to disconnect the affected server from the network to prevent further damage and spread of the attack. Once the server is isolated, the engineer can then analyze the source of the intrusion, access the affected server to confirm the compromised files are encrypted, and determine the attack surface to prevent future attacks. - ChatGPT
upvoted 1 times
...
kyle942
2 years, 3 months ago
When performing forensics during incident response, an important consideration is how and when the incident should be contained. Isolating the pertinent systems from external influences may be necessary to prevent further damage to the system and its data or to preserve evidence. In many cases, the analyst should work with the incident response team to make a containment decision (e.g., disconnecting network cables, unplugging power, increasing physical security measures, gracefully shutting down a host). This decision should be based on existing policies and procedures regarding incident containment, as well as the teamĂ­s assessment of the risk posed by the incident, so that the chosen containment strategy or combination of strategies sufficiently mitigates risk while maintaining the integrity of potential evidence whenever p
upvoted 1 times
...
Bobster02
3 years, 5 months ago
This is question # 93
upvoted 1 times
...
CiscoTester
3 years, 5 months ago
NEW Q* An employee is a victim of a social engineering phone call and installs remote access software to allow an “MS Support” technician to check his machine for malware. The employee becomes suspicious after the remote technician requests payment in the form of gift cards. The employee has copies of multiple, unencrypted database files, over 400 MB each, on his system and is worried that the scammer copied the files off but has no proof of it. The remote technician was connected sometime between 2:00 pm and 3:00 pm over https. What should be determined regarding data loss between the employee’s laptop and the remote technician’s system? A. No database files were disclosed B. The database files were disclosed C. The database files integrity was violated D. The database files were intentionally corrupted, and encryption is possible Anydesk access through HTTPS web client can only send files but not download from the sysem. Answer is A.
upvoted 1 times
...
Bobster02
3 years, 5 months ago
Selected Answer: A
A. Disconnect the affected server from the network
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago