exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 121 discussion

Actual exam question from Cisco's 350-201
Question #: 121
Topic #: 1
[All 350-201 Questions]

Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several employees report the email as suspicious, and a security analyst is investigating the reports. Which two steps should the analyst take to begin this investigation? (Choose two.)

  • A. Evaluate the intrusion detection system alerts to determine the threat source and attack surface.
  • B. Communicate with employees to determine who opened the link and isolate the affected assets.
  • C. Examine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply recommended mitigation.
  • D. Review the mail server and proxy logs to identify the impact of a potential breach.
  • E. Check the email header to identify the sender and analyze the link in an isolated environment.
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DrVoIP
9 months, 3 weeks ago
E. Check the email header to identify the sender and analyze the link in an isolated environment. B. Communicate with employees to determine who opened the link and isolate the affected assets. - ChatGPT
upvoted 1 times
...
jaciro11
1 year, 3 months ago
Selected Answer: DE
You need to check how the attack was delivered and who open the link: proxy you can check the users who open the link email you can check the users who received the link Check the email header and open the link in a sandbox Check the headers to know from where the email comes if is possible at all Open the link in a sandbox to see the behaviors D and E
upvoted 3 times
...
germx
1 year, 11 months ago
D+E is correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...