Free 350-201 Exam Braindumps (page: 6)

Page 5 of 35

An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?

  1. Host a discovery meeting and define configuration and policy updates
  2. Update the IDS/IPS signatures and reimage the affected hosts
  3. Identify the systems that have been affected and tools used to detect the attack
  4. Identify the traffic with data capture using Wireshark and review email filters

Answer(s): C



An engineer is going through vulnerability triage with company management because of a recent malware outbreak from which 21 affected assets need to be patched or remediated. Management decides not to prioritize fixing the assets and accepts the vulnerabilities. What is the next step the engineer should take?

  1. Investigate the vulnerability to prevent further spread
  2. Acknowledge the vulnerabilities and document the risk
  3. Apply vendor patches or available hot fixes
  4. Isolate the assets affected in a separate network

Answer(s): D



The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all the necessary evidence from the computing resource. What is the next step?

  1. Conduct a risk assessment of systems and applications
  2. Isolate the infected host from the rest of the subnet
  3. Install malware prevention software on the host
  4. Analyze network traffic on the host’s subnet

Answer(s): B



An engineer notices that unauthorized software was installed on the network and discovers that it was installed by a dormant user account. The engineer suspects an escalation of privilege attack and responds to the incident. Drag and drop the activities from the left into the order for the response on the right.

Select and Place:

Exhibit A:



Exhibit B:

  1. Please refer to Exhibit B for the answer.

Answer(s): A






Post your Comments and Discuss Cisco® 350-201 exam with other Community members:

350-201 Discussions & Posts