nerdexam
Cisco

350-201 · Question #38

Refer to the exhibit. For IP 192.168.1.209, what are the risk level, activity, and next step?

The correct answer is D. high risk level, malicious host, investigate further. The exhibit classifies IP 192.168.1.209 as a high-risk malicious host, and the appropriate response at this risk level is to investigate further rather than immediately isolate or sandbox.

Security Monitoring

Question

Refer to the exhibit. For IP 192.168.1.209, what are the risk level, activity, and next step?

Exhibit

350-201 question #38 exhibit

Options

  • Ahigh risk level, anomalous periodic communication, quarantine with antivirus
  • Bcritical risk level, malicious server IP, run in a sandboxed environment
  • Ccritical risk level, data exfiltration, isolate the device
  • Dhigh risk level, malicious host, investigate further

How the community answered

(43 responses)
  • A
    9% (4)
  • B
    16% (7)
  • C
    2% (1)
  • D
    72% (31)

Why each option

The exhibit classifies IP 192.168.1.209 as a high-risk malicious host, and the appropriate response at this risk level is to investigate further rather than immediately isolate or sandbox.

Ahigh risk level, anomalous periodic communication, quarantine with antivirus

Anomalous periodic communication paired with antivirus quarantine describes a beaconing or C2 callback pattern response, which does not align with the malicious host classification and high risk level shown in the exhibit.

Bcritical risk level, malicious server IP, run in a sandboxed environment

Critical risk level and sandboxed environment execution applies to suspicious unknown files or payloads being analyzed dynamically, not to a host-level threat indicator as shown in the exhibit.

Ccritical risk level, data exfiltration, isolate the device

Immediate isolation is the appropriate response for a critical risk level or confirmed active data exfiltration; the exhibit shows high risk and malicious host activity, which calls for investigation before such a disruptive containment action.

Dhigh risk level, malicious host, investigate furtherCorrect

A 'high' risk classification - as opposed to 'critical' - combined with a 'malicious host' designation indicates confirmed suspicious behavior that warrants deeper investigation to determine scope, lateral movement, and impact before taking disruptive action such as quarantine or isolation. Proceeding to investigate first ensures responders gather sufficient evidence and avoid tipping off a threat actor prematurely.

Concept tested: Host risk level interpretation and incident response triage

Source: https://www.cisco.com/c/en/us/td/docs/security/cognitive/cognitive-threat-analytics-user-guide.html

Topics

#threat intelligence#risk level assessment#malicious host#investigation workflow

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice