nerdexam
Cisco

350-201 · Question #135

Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an…

The correct answer is A. Determine the type of data stored on the affected asset, document the access logs, and engage D. Initiate a triage meeting with department leads to determine if the application is owned internally. When an unknown, ownerless application is found communicating externally over unencrypted channels, the immediate next steps are to assess data exposure risk and escalate to leadership to confirm ownership before any remediation.

Processes

Question

Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)

Options

  • ADetermine the type of data stored on the affected asset, document the access logs, and engage
  • BIdentify who installed the application by reviewing the logs and gather a user access log from the
  • CVerify user credentials on the affected asset, modify passwords, and confirm available patches
  • DInitiate a triage meeting with department leads to determine if the application is owned internally

How the community answered

(16 responses)
  • A
    81% (13)
  • B
    6% (1)
  • C
    13% (2)

Why each option

When an unknown, ownerless application is found communicating externally over unencrypted channels, the immediate next steps are to assess data exposure risk and escalate to leadership to confirm ownership before any remediation.

ADetermine the type of data stored on the affected asset, document the access logs, and engageCorrect

Determining the type of data stored on the affected asset establishes the potential breach impact, particularly given the unencrypted external communication. Documenting access logs preserves forensic evidence needed to understand the scope and timeline of the exposure.

BIdentify who installed the application by reviewing the logs and gather a user access log from the

Reviewing installation logs to identify who installed the application is a valid forensic step but is secondary - data risk and organizational ownership must be assessed before diving into log attribution.

CVerify user credentials on the affected asset, modify passwords, and confirm available patches

Verifying credentials, modifying passwords, and patching are remediation actions that are premature at this stage; the investigation must first characterize the threat and confirm ownership before applying fixes.

DInitiate a triage meeting with department leads to determine if the application is owned internallyCorrect

Initiating a triage meeting with department leads is the appropriate escalation step to determine if any business unit has undocumented ownership of the application before taking disruptive action. This prevents prematurely removing a tool that may have a legitimate but undocumented purpose.

Concept tested: Incident response steps for unknown rogue application discovery

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#application discovery#unauthorized application#incident investigation#data protection

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice