nerdexam
Cisco

350-201(NEW-127Q) · Question #110

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

The correct answer is B. Disconnect the affected server from the network. Disconnecting the affected server (B) is correct because containment is the immediate priority in incident response - isolating the compromised system stops the attacker from exfiltrating more data, moving laterally, or causing further damage. This follows the standard IR…

Incident Response and Management

Question

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

Options

  • AAccess the affected server to confirm compromised files are encrypted.
  • BDisconnect the affected server from the network.
  • CAnalyze the source.
  • DDetermine the attack surface.

How the community answered

(49 responses)
  • A
    18% (9)
  • B
    69% (34)
  • C
    8% (4)
  • D
    4% (2)

Explanation

Disconnecting the affected server (B) is correct because containment is the immediate priority in incident response - isolating the compromised system stops the attacker from exfiltrating more data, moving laterally, or causing further damage. This follows the standard IR lifecycle: Contain first, then investigate.

  • A is wrong because checking whether files are encrypted is analysis, not containment - and accessing the live server while it's still networked can destroy forensic evidence or worsen the breach.
  • C is wrong because analyzing the source is a post-containment step; acting on attribution before isolating the threat leaves the breach open.
  • D is wrong because determining the attack surface is part of scoping/preparation, not an immediate response to an active intrusion.

Memory tip: Think "PICERL" - the IR phases are Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. When a question asks what to do immediately after detecting an active breach, the answer almost always maps to Containment - and containment means cut the connection.

Topics

#Incident Response#Containment#Network Isolation#Intrusion Management

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice