nerdexam
Cisco

300-215 · Question #111

A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which…

The correct answer is C. centralized user management D. intrusion prevention system. The eradication phase in incident response involves eliminating the root cause of the incident and strengthening defenses to prevent reoccurrence. In this case: Intrusion Prevention System (D): Adding new rules to the IPS to detect and block malicious activity on TCP/135 is a…

Submitted by valeria.br· Mar 6, 2026Incident Response Processes

Question

A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which two elements are part of the eradication phase for this incident? (Choose two.)

Options

  • Aanti-malware software
  • Bdata and workload isolation
  • Ccentralized user management
  • Dintrusion prevention system
  • Eenterprise block listing solution

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    83% (29)
  • E
    9% (3)

Explanation

The eradication phase in incident response involves eliminating the root cause of the incident and strengthening defenses to prevent reoccurrence. In this case: Intrusion Prevention System (D): Adding new rules to the IPS to detect and block malicious activity on TCP/135 is a direct eradication step to remove the threat's entry point and prevent Centralized User Management (C): Hardening user accounts, removing unnecessary permissions, and applying tighter authentication/authorization measures helps eliminate the possibility that threat actors could exploit weak or mismanaged accounts to continue accessing

Topics

#incident response phases#eradication#containment#network security controls

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice