Free 300-215 Exam Braindumps (page: 7)

Page 6 of 15

What is the goal of an incident response plan?

  1. to identify critical systems and resources in an organization
  2. to ensure systems are in place to prevent an attack
  3. to determine security weaknesses and recommend solutions
  4. to contain an attack and prevent it from spreading

Answer(s): D


Reference:

https://www.forcepoint.com/cyber-edu/incident-response



A security team received an alert of suspicious activity on a user’s Internet browser. The user’s anti-virus software indicated that the file attempted to create a fake recycle bin folder and connect to an external IP address. Which two actions should be taken by the security analyst with the executable file for further analysis? (Choose two.)

  1. Evaluate the process activity in Cisco Umbrella.
  2. Analyze the TCP/IP Streams in Cisco Secure Malware Analytics (Threat Grid).
  3. Evaluate the behavioral indicators in Cisco Secure Malware Analytics (Threat Grid).
  4. Analyze the Magic File type in Cisco Umbrella.
  5. Network Exit Localization in Cisco Secure Malware Analytics (Threat Grid).

Answer(s): B,C



An employee receives an email from a “trusted” person containing a hyperlink that is malvertising. The employee clicks the link and the malware downloads. An information analyst observes an alert at the SIEM and engages the cybersecurity team to conduct an analysis of this incident in accordance with the incident response plan. Which event detail should be included in this root cause analysis?

  1. phishing email sent to the victim
  2. alarm raised by the SIEM
  3. information from the email header
  4. alert identified by the cybersecurity team

Answer(s): B



Refer to the exhibit. Which two actions should be taken based on the intelligence information? (Choose two.)

  1. Block network access to all .shop domains
  2. Add a SIEM rule to alert on connections to identified domains.
  3. Use the DNS server to block hole all .shop requests.
  4. Block network access to identified domains.
  5. Route traffic from identified domains to block hole.

Answer(s): B,D






Post your Comments and Discuss Cisco® 300-215 exam with other Community members:

300-215 Discussions & Posts