nerdexam
Cisco

200-201 · Question #530

Refer to the exhibit. A SOC team member receives a case from his colleague with notes attached. The artifacts and alerts associated with the case must be analyzed and a conclusion must be provided…

The correct answer is C. A ransomware attack is underway, encrypting files and deleting originals. The alert and associated artifacts indicate that a ransomware attack is underway, actively encrypting files and concurrently deleting the original unencrypted versions.

Submitted by marco_it· Mar 6, 2026Security Monitoring

Question

Refer to the exhibit. A SOC team member receives a case from his colleague with notes attached. The artifacts and alerts associated with the case must be analyzed and a conclusion must be provided. What is the cause of the alert?

Options

  • AAn insider threat compromised the service account to delete sensitive data.
  • BExternal attackers gained access and are exfiltrating data stealthily.
  • CA ransomware attack is underway, encrypting files and deleting originals.
  • DA misconfigured backup process malfunctioned, causing unexpected file changes.

How the community answered

(49 responses)
  • A
    14% (7)
  • B
    8% (4)
  • C
    73% (36)
  • D
    4% (2)

Why each option

The alert and associated artifacts indicate that a ransomware attack is underway, actively encrypting files and concurrently deleting the original unencrypted versions.

AAn insider threat compromised the service account to delete sensitive data.

An insider threat deleting sensitive data would primarily manifest as data loss, not typically as widespread file encryption coupled with original file deletion.

BExternal attackers gained access and are exfiltrating data stealthily.

External attackers exfiltrating data stealthily involves unauthorized data transfer outside the network, which is distinct from the on-system encryption and deletion associated with ransomware.

CA ransomware attack is underway, encrypting files and deleting originals.Correct

A ransomware attack typically involves encrypting a victim's files to render them inaccessible and often includes deleting the original unencrypted files to prevent straightforward recovery without the attacker's decryption key.

DA misconfigured backup process malfunctioned, causing unexpected file changes.

A misconfigured backup process might cause data issues or loss, but it would not deliberately encrypt files and delete their originals in a malicious pattern characteristic of an attack.

Concept tested: Identifying ransomware attack indicators

Source: https://www.cisa.gov/stopransomware/what-ransomware

Topics

#Ransomware#Incident analysis#File encryption#Data deletion

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice