350-201(NEW-127Q) · Question #5
A security analyst detected that a group of internal hosts are initiating periodic port scanning activities to different network segments and that connections are then being initiated to the…
The correct answer is A. Identify the endpoint that received suspicious email via ESA and perform a traffic analysis via StealthWatch followed by network block requests. Option A is correct because it directly addresses both goals - identification and quarantine - using the available tools in the right sequence: the ESA (Email Security Appliance) has logs of every recipient of the suspicious email, revealing which endpoints were exposed to the…
Question
Options
- AIdentify the endpoint that received suspicious email via ESA and perform a traffic analysis via StealthWatch followed by network block requests.
- BRequest the support of an external forensic investigator and investigate endpoints' suspicious activity in detail for further quarantine actions.
- CUpload the attached .doc file to ThreatGrid environment for deep understanding of suspicious activity.
- DCheck NGFW and IDS logs for related detections of possible C&C activity.
- ECheck the antivirus software logs according to the timeframe of alerts received from SIEM.
How the community answered
(33 responses)- A67% (22)
- B3% (1)
- C18% (6)
- D9% (3)
- E3% (1)
Explanation
Option A is correct because it directly addresses both goals - identification and quarantine - using the available tools in the right sequence: the ESA (Email Security Appliance) has logs of every recipient of the suspicious email, revealing which endpoints were exposed to the initial attack vector, and StealthWatch's network behavior analytics can then confirm which of those hosts are exhibiting anomalous traffic (port scanning, C&C callbacks to 10.1.4.5), enabling targeted network block requests to quarantine them.
Why the distractors are wrong:
- B is wrong because the team already has all the necessary tools in-house; escalating to an external forensic investigator is slow, expensive, and unnecessary at this stage.
- C (ThreatGrid) helps analyze what the malware does, but it doesn't help locate which other endpoints are infected - it's a sandboxing/analysis tool, not a host-discovery tool.
- D (NGFW/IDS logs) could show C&C connections to 10.1.4.5, but it's a passive historical lookup; StealthWatch gives you richer behavioral context and active response capability, making A the stronger choice.
- E is explicitly ruled out by the question itself - the AV has no alerts, so its logs contain nothing actionable.
Memory tip: Think "trace the email, watch the wire, block the host" - ESA finds who got the bait, StealthWatch finds who took it, then you block. The AV is already confirmed silent, so skip it.
Topics
Community Discussion
No community discussion yet for this question.