nerdexam
Cisco

350-201 · Question #120

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

The correct answer is A. Disconnect the affected server from the network. When personal data is confirmed accessed during an intrusion, the immediate containment action is to isolate the affected server by disconnecting it from the network.

Processes

Question

An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

Options

  • ADisconnect the affected server from the network.
  • BAnalyze the source.
  • CAccess the affected server to confirm compromised files are encrypted.
  • DDetermine the attack surface.

How the community answered

(54 responses)
  • A
    76% (41)
  • B
    4% (2)
  • C
    13% (7)
  • D
    7% (4)

Why each option

When personal data is confirmed accessed during an intrusion, the immediate containment action is to isolate the affected server by disconnecting it from the network.

ADisconnect the affected server from the network.Correct

Disconnecting the affected server from the network is the primary containment technique defined in incident response frameworks because it immediately terminates the attacker's access channel, halts further data exfiltration, and prevents lateral movement to other systems. This action preserves the server state for forensic analysis while stopping active harm.

BAnalyze the source.

Analyzing the source is a detection and analysis activity, not a containment action; it does nothing to stop ongoing unauthorized access to personal data.

CAccess the affected server to confirm compromised files are encrypted.

Accessing the server to verify encryption status is a forensic analysis step that delays containment and could alert an attacker who still has an active session.

DDetermine the attack surface.

Determining the attack surface is a scoping and analysis activity that should follow containment, not precede it when active data access is occurring.

Concept tested: Network isolation as primary incident containment action

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#intrusion containment#network isolation#data breach response#affected system

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice