nerdexam
Cisco

350-201 · Question #124

Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several…

The correct answer is D. Review the mail server and proxy logs to identify the impact of a potential breach. E. Check the email header to identify the sender and analyze the link in an isolated environment. Investigating a suspected phishing email requires verifying the sender via the email header and safely analyzing the malicious link, while reviewing mail and proxy logs to determine breach impact.

Processes

Question

Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several employees report the email as suspicious, and a security analyst is investigating the reports. Which two steps should the analyst take to begin this investigation? (Choose two.)

Options

  • AEvaluate the intrusion detection system alerts to determine the threat source and attack surface.
  • BCommunicate with employees to determine who opened the link and isolate the affected assets.
  • CExamine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply
  • DReview the mail server and proxy logs to identify the impact of a potential breach.
  • ECheck the email header to identify the sender and analyze the link in an isolated environment.

How the community answered

(49 responses)
  • A
    6% (3)
  • B
    10% (5)
  • C
    2% (1)
  • D
    82% (40)

Why each option

Investigating a suspected phishing email requires verifying the sender via the email header and safely analyzing the malicious link, while reviewing mail and proxy logs to determine breach impact.

AEvaluate the intrusion detection system alerts to determine the threat source and attack surface.

Evaluating IDS alerts is not a primary first step for phishing because the email itself typically does not trigger IDS alerts until after a payload executes or a malicious outbound connection is established.

BCommunicate with employees to determine who opened the link and isolate the affected assets.

Communicating with employees and isolating affected assets is a containment action that belongs after the initial investigation confirms a threat - performing it first disrupts the investigation before scope is known.

CExamine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply

Reviewing firewall and HIPS configurations to identify exploited vulnerabilities is a remediation-phase activity and is premature before the nature and delivery mechanism of the phishing attack are confirmed.

DReview the mail server and proxy logs to identify the impact of a potential breach.Correct

Reviewing mail server logs identifies all recipients of the suspicious email, and proxy logs reveal whether any employee clicked the provided link, directly establishing the scope and potential impact of the breach.

ECheck the email header to identify the sender and analyze the link in an isolated environment.Correct

Examining the email header exposes spoofed or forged sender information to confirm it is not a legitimate executive email, and analyzing the embedded link inside an isolated sandbox environment safely identifies the malicious payload or credential-harvesting site.

Concept tested: Phishing email investigation initial response steps

Source: https://www.cisa.gov/sites/default/files/publications/Phishing_Guidance_508c.pdf

Topics

#phishing#email investigation#proxy logs#social engineering

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice