nerdexam
Cisco

350-201(NEW-127Q) · Question #5

A security analyst detected that a group of internal hosts are initiating periodic port scanning activities to different network segments and that connections are then being initiated to the…

The correct answer is A. Identify the endpoint that received suspicious email via ESA and perform a traffic analysis via StealthWatch followed by network block requests. Option A is correct because it directly addresses both goals - identification and quarantine - using the available tools in the right sequence: the ESA (Email Security Appliance) has logs of every recipient of the suspicious email, revealing which endpoints were exposed to the…

Incident Response and Management

Question

A security analyst detected that a group of internal hosts are initiating periodic port scanning activities to different network segments and that connections are then being initiated to the 10.1.4.5 host. The company SIEM also alerted several days ago that suspicious email was sent to company mailboxes with attached .doc file. The antivirus software installed on detected endpoints has no alerts. The security team has access to the logs of Cisco NGFW, IDS, ESA, StealthWatch, and ThreatGrid. Which two methods should be used to identify and quarantine the rest of the infected endpoints? (Choose two.)

Options

  • AIdentify the endpoint that received suspicious email via ESA and perform a traffic analysis via StealthWatch followed by network block requests.
  • BRequest the support of an external forensic investigator and investigate endpoints' suspicious activity in detail for further quarantine actions.
  • CUpload the attached .doc file to ThreatGrid environment for deep understanding of suspicious activity.
  • DCheck NGFW and IDS logs for related detections of possible C&C activity.
  • ECheck the antivirus software logs according to the timeframe of alerts received from SIEM.

How the community answered

(33 responses)
  • A
    67% (22)
  • B
    3% (1)
  • C
    18% (6)
  • D
    9% (3)
  • E
    3% (1)

Explanation

Option A is correct because it directly addresses both goals - identification and quarantine - using the available tools in the right sequence: the ESA (Email Security Appliance) has logs of every recipient of the suspicious email, revealing which endpoints were exposed to the initial attack vector, and StealthWatch's network behavior analytics can then confirm which of those hosts are exhibiting anomalous traffic (port scanning, C&C callbacks to 10.1.4.5), enabling targeted network block requests to quarantine them.

Why the distractors are wrong:

  • B is wrong because the team already has all the necessary tools in-house; escalating to an external forensic investigator is slow, expensive, and unnecessary at this stage.
  • C (ThreatGrid) helps analyze what the malware does, but it doesn't help locate which other endpoints are infected - it's a sandboxing/analysis tool, not a host-discovery tool.
  • D (NGFW/IDS logs) could show C&C connections to 10.1.4.5, but it's a passive historical lookup; StealthWatch gives you richer behavioral context and active response capability, making A the stronger choice.
  • E is explicitly ruled out by the question itself - the AV has no alerts, so its logs contain nothing actionable.

Memory tip: Think "trace the email, watch the wire, block the host" - ESA finds who got the bait, StealthWatch finds who took it, then you block. The AV is already confirmed silent, so skip it.

Topics

#Incident Response#Endpoint Detection#Security Tool Integration#Threat Investigation

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice