nerdexam
Cisco

350-201(NEW-127Q) · Question #107

A company was breached by phishing emails by a third-party partner email domain. Multiple employees were infected by ransomware. The incident response team detected the breach after data on the…

The correct answer is C. Block the compromised domain and quarantine the infected endpoint. Note: This question asks for two correct answers - both C and E are correct (the answer key you shared appears incomplete). C is correct because containment must happen before recovery: blocking the compromised phishing domain stops ongoing infections, and quarantining infected…

Incident Response and Management

Question

A company was breached by phishing emails by a third-party partner email domain. Multiple employees were infected by ransomware. The incident response team detected the breach after data on the critical server became encrypted and web applications crashed. Security engineers requested recovery actions for affected servers. According to incident response processes, which two steps were missed by security staff? (Choose two.)

Options

  • APerform an investigation and prepare an incident report for the CISO.
  • BBlock connections to C&C and decrypt the data on endpoints.
  • CBlock the compromised domain and quarantine the infected endpoint.
  • DRequest that an external security vendor perform forensics actions.
  • EDetermine the attack source and IOCs of the breach.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    81% (29)
  • E
    6% (2)

Explanation

Note: This question asks for two correct answers - both C and E are correct (the answer key you shared appears incomplete).

C is correct because containment must happen before recovery: blocking the compromised phishing domain stops ongoing infections, and quarantining infected endpoints prevents ransomware from spreading laterally to other systems. Jumping straight to recovery without containment leaves the threat active.

E is also correct because identifying the attack source and indicators of compromise (IOCs) is a required analysis step before remediation - without knowing how the malware behaved and what it touched, recovery actions may be incomplete or ineffective.

Why the others are wrong:

  • A - An incident report for the CISO is a post-incident activity, not a missed mid-response step.
  • B - Blocking C2 (command-and-control) is valid, but decrypting ransomware data is generally not a standard IR action you can simply perform - it's not a "missed step."
  • D - Calling an external forensics vendor may be appropriate in some cases, but it's not a universally required IR step that was definitively missed here.

Memory tip: Think of the IR lifecycle as Detect → Contain → Analyze → Eradicate → Recover. In this scenario, the team skipped straight from Detect to Recover - missing Contain (block/quarantine = C) and Analyze (IOCs/source = E).

Topics

#Incident Response#Containment#Endpoint Quarantine#C&C Blocking

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice