350-201(NEW-127Q) · Question #111
An employee who frequently travels abroad connects to a company network from a first-seen country during nonworking hours. The SIEM tool generated an alert that the employee forwarded an excessive…
The correct answer is B. Immediately suspend the employee's account and notify senior management about the incident. Option B is correct because the described behavior - accessing the network from an unfamiliar country after hours, then bulk-forwarding emails to a competitor's domain - constitutes strong indicators of insider data exfiltration, an active threat requiring immediate…
Question
Options
- AReboot the employee's device and run a comprehensive malware scan on the system.
- BImmediately suspend the employee's account and notify senior management about the incident.
- CEnhance anomaly detection capabilities and update data handling policies to prevent data loss.
- DReview the company's travel policies and implement multi-factor authentication for all users.
- EConduct a detailed forensic investigation of the employee's device and email activities.
How the community answered
(33 responses)- A9% (3)
- B64% (21)
- C6% (2)
- D3% (1)
- E18% (6)
Explanation
Option B is correct because the described behavior - accessing the network from an unfamiliar country after hours, then bulk-forwarding emails to a competitor's domain - constitutes strong indicators of insider data exfiltration, an active threat requiring immediate containment. Suspending the account stops ongoing damage, and escalating to senior management triggers the incident response chain per most security frameworks (e.g., NIST IR). Note that since the question says "Choose two," E is almost certainly the second correct answer, as a forensic investigation of the device and email activities is the essential follow-up to gather evidence and understand the full scope of the breach.
Why the distractors are wrong:
- A - Rebooting the device is counterproductive; it can destroy volatile forensic evidence (RAM, active processes). Malware isn't indicated here - this is a behavioral/insider threat scenario.
- C - Updating detection policies and data loss prevention is a long-term improvement, not an immediate incident response action.
- D - Reviewing travel policies and rolling out MFA are preventive/administrative controls, appropriate after the incident is resolved, not during active response.
Memory tip: Use the "Contain → Investigate → Improve" sequence for incident response questions. Immediate containment (B) comes first, forensics (E) comes second, and policy/technical improvements (C, D) come last. If you see active exfiltration indicators, always stop the bleeding before analyzing or improving.
Topics
Community Discussion
No community discussion yet for this question.