nerdexam
Cisco

350-201(NEW-127Q) · Question #67

An EDR system alerted the incident response team about the activity of malicious files on the HR manager endpoint. The infected endpoint was isolated from the network. Further examination of the…

The correct answer is D. Investigate other employees' endpoints and quarantine infected ones. Option D is correct because the scenario is still in the Containment phase of NIST 800-61's cycle (Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity). The HR endpoint was isolated (short-term containment), but since phishing…

Incident Response and Management

Question

An EDR system alerted the incident response team about the activity of malicious files on the HR manager endpoint. The infected endpoint was isolated from the network. Further examination of the incidents shows that the source of this file was the phishing emails sent to company employees. According to the NIST 800-61 incident handling workflow, what is the next step in handling the incident?

Options

  • AAnalyze the attack vector and prepare the incident report for management.
  • BSend warning emails to vulnerable employees.
  • CEradicate the malicious file from infected endpoints of HR managers.
  • DInvestigate other employees' endpoints and quarantine infected ones.

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    13% (3)
  • C
    4% (1)
  • D
    74% (17)

Explanation

Option D is correct because the scenario is still in the Containment phase of NIST 800-61's cycle (Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity). The HR endpoint was isolated (short-term containment), but since phishing emails targeted multiple employees, the team must determine the full scope of infection by investigating other endpoints and quarantining any compromised ones before moving forward - otherwise eradication would be incomplete.

Why the distractors are wrong:

  • A is wrong because incident reporting for management is a Post-Incident Activity step, not something done while the threat is still active and unscoped.
  • B is wrong because warning emails, while useful, are not the prioritized next step in the NIST workflow - you must finish containing the threat before shifting to awareness messaging.
  • C is wrong because eradication comes after full containment; cleaning only the HR manager's machine while other infected endpoints remain active would leave the incident unresolved.

Memory tip: Think of NIST 800-61 containment as "catch them all before you clean" - you must identify and quarantine every infected system before eradicating anything, especially when a phishing campaign implies multiple potential victims.

Topics

#Incident Response#NIST 800-61#Containment#Scope Assessment

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice