300-740 · Question #41
Refer to the exhibit. An engineer is investigating the critical alert received in Cisco Secure Network Analytics. The engineer confirms that the incident is valid. Which two actions must be taken?…
The correct answer is A. Inform the incident management team. B. Block IP address 66.77.197.165. When a confirmed security incident is detected in Cisco Secure Network Analytics, the immediate response follows the IR playbook: notify the incident management team (A) to coordinate the formal response, and block the offending external IP address 66.77.197.165 (B) to cut off…
Question
Refer to the exhibit. An engineer is investigating the critical alert received in Cisco Secure Network Analytics. The engineer confirms that the incident is valid. Which two actions must be taken? (Choose two.)
Exhibit
Options
- AInform the incident management team.
- BBlock IP address 66.77.197.165
- CUninstall the Conduit software.
- DShut down the host.
- EQuarantine the host
How the community answered
(33 responses)- A79% (26)
- C12% (4)
- D3% (1)
- E6% (2)
Explanation
When a confirmed security incident is detected in Cisco Secure Network Analytics, the immediate response follows the IR playbook: notify the incident management team (A) to coordinate the formal response, and block the offending external IP address 66.77.197.165 (B) to cut off the active threat vector at the network level.
Why the distractors are wrong:
- C (Uninstall Conduit software): "Conduit" is likely the malware or suspicious software identified - uninstalling it is a remediation step that comes after containment is established, and only after forensic evidence is preserved. Rushing to uninstall destroys evidence.
- D (Shut down the host): Powering down a compromised host destroys volatile memory (RAM), which contains critical forensic artifacts like running processes and active connections. Isolation/quarantine is preferred over shutdown.
- E (Quarantine the host): This seems plausible, but quarantine is a deeper containment action typically taken after notifying the incident management team - the team decides the containment strategy. On its own without notification, acting unilaterally bypasses proper IR procedure. The question prioritizes the must-do-first actions.
Memory tip: Think "Notify + Block" as the first two pillars of incident response - humans in the loop (A) and network containment (B). Never destroy evidence (D) and never skip the chain of command (missing E without A).
Topics
Community Discussion
No community discussion yet for this question.
