nerdexam
Cisco

350-201(NEW-127Q) · Question #26

A security analyst monitors an organization's network using UEBA tools to detect potential threats. During the analysis, the analyst notices unusual activities, such as a user from the marketing…

The correct answer is D. Investigate potential insider threats, assess unauthorized access, and analyze VPN security configurations. Option D directly addresses the three specific anomalies observed: insider threat investigation covers the marketing user accessing finance files, unauthorized access assessment covers the executive's unrecognized IP login, and VPN security analysis covers the surge in failed…

Threat Detection and Response

Question

A security analyst monitors an organization's network using UEBA tools to detect potential threats. During the analysis, the analyst notices unusual activities, such as a user from the marketing department accessing the finance department file server during non-business hours, a senior executive logging into the HR system from an unrecognized IP address, and a sudden increase in the number of failed login attempts on the company VPN. Based on the anomalous user entity behavior observed, which actions should the security analyst prioritize?

Options

  • AUpdate antivirus software, deploy an intrusion detection system, and perform regular vulnerability scans.
  • BConduct security awareness training, implement multifactor authentication, and review network segmentation.
  • CImplement a stricter password policy, deploy a Web Application Firewall, and establish a Security Operations Center.
  • DInvestigate potential insider threats, assess unauthorized access, and analyze VPN security configurations.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    17% (5)
  • C
    10% (3)
  • D
    67% (20)

Explanation

Option D directly addresses the three specific anomalies observed: insider threat investigation covers the marketing user accessing finance files, unauthorized access assessment covers the executive's unrecognized IP login, and VPN security analysis covers the surge in failed login attempts. UEBA tools are designed to surface exactly these behavioral anomalies, so the analyst's first priority should be triaging and investigating what UEBA has already flagged - not deploying new tools.

Why the distractors fail:

  • A introduces antivirus and IDS - reactive/preventive controls that don't address the behavioral incidents already in progress.
  • B (awareness training, MFA, segmentation) describes good long-term hygiene but are strategic/remediation steps, not immediate incident response actions.
  • C (password policy, WAF, SOC) are infrastructure and governance improvements - valid eventually, but a WAF specifically protects web applications, not the file server or VPN scenarios described.

Memory tip: When a question describes specific, active anomalies already detected, the correct answer will always respond to those specific anomalies rather than deploy new tools or run training. Match the action to the observable evidence - UEBA detected behavior problems, so the answer is behavioral investigation (D), not infrastructure additions.

Topics

#UEBA#Insider Threat Detection#Incident Response#Behavioral Analytics

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice