nerdexam
Cisco

200-201 · Question #479

The SOC team has confirmed a potential indicator of compromise on an isolated endpoint. The team has narrowed the potential malware type to a new trojan family. According to the NIST Computer Security

Sign in or unlock 200-201 to reveal the answer and full explanation for question #479. The question stem and answer options stay visible for context.

Submitted by helene.fr· Mar 6, 2026Security Policies and Procedures

Question

The SOC team has confirmed a potential indicator of compromise on an isolated endpoint. The team has narrowed the potential malware type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling the event?

Options

  • APerform an AV scan on the infected endpoint.
  • BIsolate the infected endpoint from the network.
  • CPrioritize incident handling based on the impact.
  • DAnalyze the malware behavior.

Unlock 200-201 to see the answer

You've previewed enough free 200-201 questions. Unlock 200-201 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident response#NIST SP 800-61#malware analysis#security operations
Full 200-201 Practice