nerdexam
Cisco

300-215 · Question #94

An engineer is investigating a ticket from the accounting department in which a user discovered an unexpected application on their workstation. Several alerts are seen from the intrusion detection…

The correct answer is C. Disconnect from the network. E. Take an image of the workstation. When suspicious activity is detected on a workstation, immediate steps need to be taken to preserve evidence and prevent further compromise: Disconnecting the system from the network (C) is crucial to stop potential exfiltration of data or ongoing communications with a…

Submitted by andres_qro· Mar 6, 2026Incident Response Techniques

Question

An engineer is investigating a ticket from the accounting department in which a user discovered an unexpected application on their workstation. Several alerts are seen from the intrusion detection system of unknown outgoing internet traffic from this workstation. The engineer also notices a degraded processing capability, which complicates the analysis process. Which two actions should the engineer take? (Choose two.)

Options

  • ARestore to a system recovery point.
  • BReplace the faulty CPU.
  • CDisconnect from the network.
  • DFormat the workstation drives.
  • ETake an image of the workstation.

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    82% (28)
  • D
    9% (3)

Explanation

When suspicious activity is detected on a workstation, immediate steps need to be taken to preserve evidence and prevent further compromise: Disconnecting the system from the network (C) is crucial to stop potential exfiltration of data or ongoing communications with a command-and-control server. This isolation prevents further spread or damage while preserving the state of the compromised system for further investigation. Taking an image of the workstation (E) is part of the forensics acquisition process. It involves creating a bit-by-bit copy of the system's disk, which preserves all evidence in its current state. This allows for thorough forensic analysis without affecting the original evidence. Specifically, in the Identification and Containment phases of the incident response cycle, it's emphasized that isolating the system and preserving evidence through imaging are critical to ensuring both containment of the threat and successful forensic investigation.

Topics

#incident response#endpoint compromise#evidence collection#network isolation

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice