nerdexam
Cisco

350-201(NEW-127Q) · Question #111

An employee who frequently travels abroad connects to a company network from a first-seen country during nonworking hours. The SIEM tool generated an alert that the employee forwarded an excessive…

The correct answer is B. Immediately suspend the employee's account and notify senior management about the incident. Option B is correct because the described behavior - accessing the network from an unfamiliar country after hours, then bulk-forwarding emails to a competitor's domain - constitutes strong indicators of insider data exfiltration, an active threat requiring immediate…

Incident Handling and Response

Question

An employee who frequently travels abroad connects to a company network from a first-seen country during nonworking hours. The SIEM tool generated an alert that the employee forwarded an excessive number of emails to an external domain address and then logged off. The securing analyst investigating this event concluded that the external domain belongs to a competing organization. What should be the next two sets of actions based on the observed user behavior? (Choose two)

Options

  • AReboot the employee's device and run a comprehensive malware scan on the system.
  • BImmediately suspend the employee's account and notify senior management about the incident.
  • CEnhance anomaly detection capabilities and update data handling policies to prevent data loss.
  • DReview the company's travel policies and implement multi-factor authentication for all users.
  • EConduct a detailed forensic investigation of the employee's device and email activities.

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    64% (21)
  • C
    6% (2)
  • D
    3% (1)
  • E
    18% (6)

Explanation

Option B is correct because the described behavior - accessing the network from an unfamiliar country after hours, then bulk-forwarding emails to a competitor's domain - constitutes strong indicators of insider data exfiltration, an active threat requiring immediate containment. Suspending the account stops ongoing damage, and escalating to senior management triggers the incident response chain per most security frameworks (e.g., NIST IR). Note that since the question says "Choose two," E is almost certainly the second correct answer, as a forensic investigation of the device and email activities is the essential follow-up to gather evidence and understand the full scope of the breach.

Why the distractors are wrong:

  • A - Rebooting the device is counterproductive; it can destroy volatile forensic evidence (RAM, active processes). Malware isn't indicated here - this is a behavioral/insider threat scenario.
  • C - Updating detection policies and data loss prevention is a long-term improvement, not an immediate incident response action.
  • D - Reviewing travel policies and rolling out MFA are preventive/administrative controls, appropriate after the incident is resolved, not during active response.

Memory tip: Use the "Contain → Investigate → Improve" sequence for incident response questions. Immediate containment (B) comes first, forensics (E) comes second, and policy/technical improvements (C, D) come last. If you see active exfiltration indicators, always stop the bleeding before analyzing or improving.

Topics

#Incident Response#Data Exfiltration#Insider Threats#Account Suspension

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice