nerdexam
Cisco

350-201(NEW-127Q) · Question #23

A security analyst is reviewing a playbook scenario that describes the steps to be taken in response to a phishing attack targeting the organization. The scenario includes the identification and…

The correct answer is D. Email filtering solution, malware analysis sandbox, and incident response management platform. Option D is correct because each tool directly maps to a step in the playbook: an email filtering solution identifies and contains phishing emails at the delivery layer, a malware analysis sandbox safely analyzes suspicious payloads in isolation, and an incident response…

Incident Response and Management

Question

A security analyst is reviewing a playbook scenario that describes the steps to be taken in response to a phishing attack targeting the organization. The scenario includes the identification and containment of phishing emails, analysis of potential malware payloads, and communication w affected users. Based on this playbook scenario, which combination of tools should the analyst determine is necessary to effectively respond to the phishing attack?

Options

  • AIntrusion detection system, network packet analyzer, and SIEM
  • BDLP solution, WAF, and multifactor authentication system
  • CVulnerability scanner, penetration testing tool, and UEBA system
  • DEmail filtering solution, malware analysis sandbox, and incident response management platform

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    11% (4)
  • D
    82% (31)

Explanation

Option D is correct because each tool directly maps to a step in the playbook: an email filtering solution identifies and contains phishing emails at the delivery layer, a malware analysis sandbox safely analyzes suspicious payloads in isolation, and an incident response management platform coordinates communication with affected users and tracks the response workflow - covering all three described phases.

Option A (IDS, packet analyzer, SIEM) focuses on network-level detection and log aggregation - useful for broader threat monitoring, but none of these tools specifically address phishing email containment or malware detonation.

Option B (DLP, WAF, MFA) are preventive/access control tools. They reduce attack surface but do not help respond to an active phishing incident already in progress.

Option C (vulnerability scanner, pen testing tool, UEBA) are offensive/behavioral analytics tools used for proactive security assessments, not incident response to a live phishing attack.

Memory tip: Match each tool to a playbook phase - Filter (stop the email) → Sandbox (analyze the payload) → IRP (manage and communicate). If the scenario describes a phishing response workflow with three phases, look for the answer that has exactly one tool per phase.

Topics

#Incident Response#Phishing Detection#Email Security#Malware Analysis

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice