nerdexam
Cisco

350-201 · Question #19

Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startup folder. It…

The correct answer is C. Identify affected systems. When multiple systems show signs of the same infection, scoping the incident by identifying all affected systems is the critical next step before performing remediation or deeper forensic investigation.

Host-Based Analysis

Question

Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startup folder. It appears that the shortcuts redirect users to malicious URLs. What is the next step the engineer should take to investigate this case?

Options

  • ARemove the shortcut files
  • BCheck the audit logs
  • CIdentify affected systems
  • DInvestigate the malicious URLs

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    15% (4)
  • C
    70% (19)
  • D
    7% (2)

Why each option

When multiple systems show signs of the same infection, scoping the incident by identifying all affected systems is the critical next step before performing remediation or deeper forensic investigation.

ARemove the shortcut files

Removing shortcut files is a remediation action that should occur after the scope of the incident is fully understood, not before other affected systems are identified.

BCheck the audit logs

Checking audit logs on a single machine is useful for deeper forensic work but does not address the broader concern that multiple systems may be compromised simultaneously.

CIdentify affected systemsCorrect

Identifying all affected systems determines the full scope and blast radius of the incident. Because multiple employees reported crashes in the same week, the malicious shortcuts likely exist on more than one machine. Scoping the incident first ensures that remediation and investigation efforts address every compromised endpoint, preventing reinfection from untouched systems.

DInvestigate the malicious URLs

Investigating the malicious URLs is a threat intelligence step that should follow scope identification, as it does not help determine which or how many systems are currently affected.

Concept tested: Incident response scoping and containment prioritization

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#malware persistence#startup folder#incident response#affected systems

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice