nerdexam
Cisco

350-201(NEW-127Q) · Question #76

An organization detected unauthorized access to its customer database that contains sensitive PII. The incident response team must respond swiftly using automation and escalation protocols to…

The correct answer is C. Leverage automated playbooks to trigger network segmentation, relevant machine isolation, and automatically gather forensic details from potentially compromised hosts. Option C is correct because it aligns with modern incident response best practices: automation + speed + scoped containment. Automated playbooks enable immediate network segmentation and host isolation without human delay, while simultaneously gathering forensic evidence…

Incident Response and Containment

Question

An organization detected unauthorized access to its customer database that contains sensitive PII. The incident response team must respond swiftly using automation and escalation protocols to minimize the impact of the breach. The infrastructure is a hybrid cloud with third-party integrations, which makes containment complex. The automated systems can perform network segmentation, trigger incident playbooks, and perform real-time log analysis. Which workflow should the team implement to ensure a highly efficient, scalable, and secure response?

Options

  • ADeploy additional IDS, manually inspect system logs for anomalies, escalate to external incident response consultants, and apply forensics tools to identify data exfiltration.
  • BManually disable third-party integrations, escalate to cloud service providers, initiate full packet capture, and enforce policy-based user account restrictions.
  • CLeverage automated playbooks to trigger network segmentation, relevant machine isolation, and automatically gather forensic details from potentially compromised hosts.
  • DAutomate full system shutdown, escalate directly to compliance auditors, and enforce organization-wide password resets to prevent further access.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    17% (5)
  • C
    69% (20)
  • D
    10% (3)

Explanation

Option C is correct because it aligns with modern incident response best practices: automation + speed + scoped containment. Automated playbooks enable immediate network segmentation and host isolation without human delay, while simultaneously gathering forensic evidence - satisfying both the containment and investigation phases of the incident response lifecycle in a scalable, repeatable way.

Why the distractors fail:

  • A relies heavily on manual log inspection and external consultants, introducing delays that worsen breach impact - the opposite of "swift" response.
  • B manually disabling third-party integrations and initiating full packet capture is operationally slow and resource-intensive; it doesn't leverage the automation already available.
  • D is too aggressive and indiscriminate - a full system shutdown disrupts business continuity, and escalating directly to compliance auditors skips the technical containment phase entirely; password resets alone don't address an active compromise.

Memory tip: Think "Automate, Isolate, Investigate" - in any incident response question involving automation capabilities, the correct answer will use them to contain first, gather evidence simultaneously, never skip to auditors or shut everything down blindly.

Topics

#Incident Response#Security Automation#Network Containment#Digital Forensics

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice