nerdexam
Cisco

200-201 · Question #304

A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch. What are the two next steps of the SOC team

The correct answer is B. Isolate affected endpoints and take disk images for analysis. E. Detect the attack vector and analyze C&C connections.. Isolate affected endpoints and take disk images for analysis: Isolating affected endpoints helps prevent further potential damage or spread of the attack. Taking disk images enables a thorough forensic analysis of the affected endpoints to understand the extent of the compromise

Submitted by hans_de· Mar 6, 2026Security Policies and Procedures

Question

A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch. What are the two next steps of the SOC team according to the NIST.SP800-61 incident handling process? (Choose two.)

Options

  • AUpdate antivirus signature databases on affected endpoints to block connections to C&C.
  • BIsolate affected endpoints and take disk images for analysis.
  • CBlock connection to this C&C server on the perimeter next-generation firewall.
  • DProvide security awareness training to HR managers and employees
  • EDetect the attack vector and analyze C&C connections.

How the community answered

(52 responses)
  • A
    13% (7)
  • B
    56% (29)
  • C
    25% (13)
  • D
    6% (3)

Explanation

Isolate affected endpoints and take disk images for analysis: Isolating affected endpoints helps prevent further potential damage or spread of the attack. Taking disk images enables a thorough forensic analysis of the affected endpoints to understand the extent of the compromise and gather evidence for further investigation. Detect the attack vector and analyze C&C connections: Analyzing the attack vector helps in understanding how the attack occurred and identifying potential vulnerabilities or weaknesses in the network or systems. Analyzing Command and Control (C&C) connections provides insights into the attacker's methods, tactics, and the scope of the compromise, aiding in the response

Topics

#Incident Response#NIST SP 800-61#Containment#Analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice