300-740 · Question #33
A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the machine is infected by…
The correct answer is D. Start isolation of the machine on the Computers tab. Option D is correct because when an endpoint is confirmed to be infected with a trojan, the immediate containment priority is to isolate the machine from the network to prevent lateral movement, further data exfiltration, or C2 communication. Cisco Secure Endpoint's Isolation…
Question
A security analyst detects an employee endpoint making connections to a malicious IP on the internet and downloaded a file named Test0511127691C.pdf. The analyst discovers the machine is infected by trojan malware. What must the analyst do to mitigate the threat using Cisco Secure Endpoint?
Options
- AIdentify the malicious IPs and place them in a blocked list
- BCreate an IP Block list and add the IP address of the affected endpoint
- CEnable scheduled scans to detect and block the executable files
- DStart isolation of the machine on the Computers tab
How the community answered
(39 responses)- A3% (1)
- B8% (3)
- C5% (2)
- D85% (33)
Explanation
Option D is correct because when an endpoint is confirmed to be infected with a trojan, the immediate containment priority is to isolate the machine from the network to prevent lateral movement, further data exfiltration, or C2 communication. Cisco Secure Endpoint's Isolation feature on the Computers tab does exactly this - it cuts off all network access to the infected host while allowing the analyst to continue investigating it remotely through the Secure Endpoint console.
Why the distractors are wrong:
- A - Blocking the malicious IP at a network/endpoint level is a reactive measure that addresses one indicator but doesn't contain the already-infected machine; the trojan may use other IPs or already have a foothold.
- B - Blocking the endpoint's own IP doesn't make sense for malware mitigation; that would disrupt legitimate traffic and doesn't remove the infection.
- C - Scheduled scans are a preventive/detective control, not an immediate containment action; they're too slow and passive when an active infection is confirmed.
Memory tip: Think "Isolate first, investigate second." In incident response, containment always comes before eradication. The word "Isolation" in Cisco Secure Endpoint maps directly to the containment phase of the NIST IR lifecycle - if you see an active trojan on an endpoint, your first tool is isolation, not scanning or blocking.
Topics
Community Discussion
No community discussion yet for this question.