300-740 · Question #40
Refer to the exhibit. An engineer is investigating an unauthorized connection issue using Cisco Secure Cloud Analytics. Which two actions must be taken? (Choose two.)
The correct answer is B. Inform the incident management team. D. Block the unwanted IP addresses on the firewall. When Cisco Secure Cloud Analytics detects an unauthorized connection, the immediate priority is containment and notification - not remediation. B (Inform the incident management team) is correct because any confirmed unauthorized connection is a security incident requiring…
Question
Refer to the exhibit. An engineer is investigating an unauthorized connection issue using Cisco Secure Cloud Analytics. Which two actions must be taken? (Choose two.)
Exhibits
Options
- AReinstall the host from a recent backup.
- BInform the incident management team.
- CValidate the IDS logs
- DBlock the unwanted IP addresses on the firewall
- EReinstall the host from scratch.
How the community answered
(30 responses)- A3% (1)
- B80% (24)
- C10% (3)
- E7% (2)
Explanation
When Cisco Secure Cloud Analytics detects an unauthorized connection, the immediate priority is containment and notification - not remediation. B (Inform the incident management team) is correct because any confirmed unauthorized connection is a security incident requiring formal escalation; the IR team coordinates the response, documents the event, and determines scope. D (Block the unwanted IP addresses on the firewall) is correct because it stops the active threat immediately - containment always precedes deeper investigation or remediation.
Why the distractors fail:
- A (Reinstall from backup) is premature and risky - you haven't confirmed full compromise, and the backup itself may be tainted.
- C (Validate IDS logs) is a deeper forensic step, not an immediate required action - Cisco SCA already surfaced the alert, so IDS log review comes later during analysis, not as a first response.
- E (Reinstall from scratch) is a late-stage remediation action reserved for confirmed, unrecoverable compromises - jumping here skips containment and evidence preservation entirely.
Memory tip: Think "Notify + Neutralize" - in any incident, you always tell the right people (B) and cut off the attacker (D) before you ever touch the affected host. Reinstalling anything before containment is like changing the locks after the burglar is still inside.
Topics
Community Discussion
No community discussion yet for this question.

