nerdexam
Cisco

300-740 · Question #5

Refer to the exhibit. A security engineer deployed Cisco Secure XDR, and during testing, the log entry shows a security incident. Which action must the engineer take first?

The correct answer is C. Isolate the endpoint. Isolating the endpoint is the correct first action because it immediately contains the threat by cutting off the compromised machine from the network, preventing lateral movement or data exfiltration while preserving the system's state for forensic investigation. Why the…

Threat Response

Question

Refer to the exhibit. A security engineer deployed Cisco Secure XDR, and during testing, the log entry shows a security incident. Which action must the engineer take first?

Options

  • AUninstall the malware.
  • BBlock IP address 10.77.17.45.
  • CIsolate the endpoint.
  • DRebuild the endpoint.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    79% (34)
  • D
    12% (5)

Explanation

Isolating the endpoint is the correct first action because it immediately contains the threat by cutting off the compromised machine from the network, preventing lateral movement or data exfiltration while preserving the system's state for forensic investigation.

Why the distractors are wrong:

  • A (Uninstall malware): You can't safely remediate what you haven't fully analyzed, and attempting removal on an active, connected endpoint risks spreading the threat first.
  • B (Block IP 10.77.17.45): Blocking the suspicious IP at the network level is a useful secondary step, but it doesn't stop malware already executing on the endpoint from using other channels or causing damage.
  • D (Rebuild the endpoint): Rebuilding is a late-stage recovery action - doing it first destroys forensic evidence and skips containment and analysis entirely.

Memory tip: Think of incident response like a fire - you contain it first (isolate), then investigate the cause, then extinguish it (remove malware), and finally rebuild what was damaged. The order matters: contain before you cure.

Topics

#Incident Response#Endpoint Isolation#Threat Containment#Cisco Secure XDR

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice