nerdexam
Cisco

350-201(NEW-127Q) · Question #110

350-201(NEW-127Q) Question #110: Real Exam Question with Answer & Explanation

Sign in or unlock 350-201(NEW-127Q) to reveal the answer and full explanation for question #110. The question stem and answer options stay visible for context.

Incident Response and Management

Question

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

Options

  • AAccess the affected server to confirm compromised files are encrypted.
  • BDisconnect the affected server from the network.
  • CAnalyze the source.
  • DDetermine the attack surface.

Unlock 350-201(NEW-127Q) to see the answer

You've previewed enough free 350-201(NEW-127Q) questions. Unlock 350-201(NEW-127Q) for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Incident Response#Containment#Network Isolation#Intrusion Management
Full 350-201(NEW-127Q) Practice