350-201 · Question #38
Refer to the exhibit. For IP 192.168.1.209, what are the risk level, activity, and next step?
The correct answer is D. high risk level, malicious host, investigate further. The exhibit classifies IP 192.168.1.209 as a high-risk malicious host, and the appropriate response at this risk level is to investigate further rather than immediately isolate or sandbox.
Question
Refer to the exhibit. For IP 192.168.1.209, what are the risk level, activity, and next step?
Exhibit
Options
- Ahigh risk level, anomalous periodic communication, quarantine with antivirus
- Bcritical risk level, malicious server IP, run in a sandboxed environment
- Ccritical risk level, data exfiltration, isolate the device
- Dhigh risk level, malicious host, investigate further
How the community answered
(43 responses)- A9% (4)
- B16% (7)
- C2% (1)
- D72% (31)
Why each option
The exhibit classifies IP 192.168.1.209 as a high-risk malicious host, and the appropriate response at this risk level is to investigate further rather than immediately isolate or sandbox.
Anomalous periodic communication paired with antivirus quarantine describes a beaconing or C2 callback pattern response, which does not align with the malicious host classification and high risk level shown in the exhibit.
Critical risk level and sandboxed environment execution applies to suspicious unknown files or payloads being analyzed dynamically, not to a host-level threat indicator as shown in the exhibit.
Immediate isolation is the appropriate response for a critical risk level or confirmed active data exfiltration; the exhibit shows high risk and malicious host activity, which calls for investigation before such a disruptive containment action.
A 'high' risk classification - as opposed to 'critical' - combined with a 'malicious host' designation indicates confirmed suspicious behavior that warrants deeper investigation to determine scope, lateral movement, and impact before taking disruptive action such as quarantine or isolation. Proceeding to investigate first ensures responders gather sufficient evidence and avoid tipping off a threat actor prematurely.
Concept tested: Host risk level interpretation and incident response triage
Source: https://www.cisco.com/c/en/us/td/docs/security/cognitive/cognitive-threat-analytics-user-guide.html
Topics
Community Discussion
No community discussion yet for this question.
