nerdexam
Cisco

350-201(NEW-127Q) · Question #8

During a routine security audit, a cybersecurity team at a multinational corporation discovers a complex security breach involving exfiltration of sensitive data. The threat has affected multiple…

The correct answer is B. Isolate affected systems, determine the extent of the breach, remove the intrusion, restore operations, and review the incident. Option B correctly follows the industry-standard incident response lifecycle: contain → identify → eradicate → recover → review. Isolating affected systems first prevents the breach from spreading further, then scoping the damage informs an effective eradication strategy, and…

Incident Response and Management

Question

During a routine security audit, a cybersecurity team at a multinational corporation discovers a complex security breach involving exfiltration of sensitive data. The threat has affected multiple systems across different departments. In line with their incident response workflow, which set of actions should the team take to effectively manage and mitigate this multifaceted incident?

Options

  • AFocus on removing the threat first, then identifying the compromised systems, followed by restoration and a final review.
  • BIsolate affected systems, determine the extent of the breach, remove the intrusion, restore operations, and review the incident.
  • CConduct an immediate review to hypothesize about the breach source, then proceed with system isolation and threat eradication.
  • DBegin with restoring operations, then move to isolating systems, analyzing the breach, and concluding with an incident review.

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    78% (21)
  • C
    11% (3)
  • D
    7% (2)

Explanation

Option B correctly follows the industry-standard incident response lifecycle: contain → identify → eradicate → recover → review. Isolating affected systems first prevents the breach from spreading further, then scoping the damage informs an effective eradication strategy, and only after the threat is removed can safe restoration begin.

Why the distractors fail:

  • A skips scoping before eradication - removing a threat without knowing its full extent risks missing compromised systems and leaving the attacker persistent access.
  • C inverts the priority by theorizing before containing, allowing active exfiltration to continue while the team hypothesizes.
  • D restores operations into a still-active threat environment, which can re-infect clean systems and compounds the damage.

Memory tip: Use the acronym I-DERE - Isolate, Determine, Eradicate, Restore, Evaluate - to lock in the correct sequence for any incident response question.

Topics

#Incident Response#Data Breach Containment#Threat Eradication#Post-Incident Analysis

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice