nerdexam
Cisco

350-201 · Question #59

A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while…

The correct answer is C. Identify systems or services at risk. After validating an active intrusion, the incident response team must determine the scope and potential impact before taking targeted remediation actions.

Processes

Question

A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while traveling. The attacker has the user's credentials and is attempting to connect to the network. What is the next step in handling the incident?

Options

  • ABlock the source IP from the firewall
  • BPerform an antivirus scan on the laptop
  • CIdentify systems or services at risk
  • DIdentify lateral movement

How the community answered

(49 responses)
  • A
    12% (6)
  • B
    2% (1)
  • C
    82% (40)
  • D
    4% (2)

Why each option

After validating an active intrusion, the incident response team must determine the scope and potential impact before taking targeted remediation actions.

ABlock the source IP from the firewall

Blocking the source IP is a reactive containment measure that does not address the full threat, since the attacker holds valid credentials and can reconnect from any IP address.

BPerform an antivirus scan on the laptop

Running an antivirus scan is a containment or eradication step focused on a single device, skipping the essential scoping phase needed to understand the full incident impact.

CIdentify systems or services at riskCorrect

Identifying systems or services at risk is the critical next step because it establishes the blast radius of the incident before containment actions are prioritized. The attacker holds valid credentials and a deployed remote access tool, meaning multiple systems could be targeted - scoping this exposure is required to respond effectively.

DIdentify lateral movement

Identifying lateral movement is an investigative activity that follows scoping - responders must first know which systems are at risk before tracing attacker movement between them.

Concept tested: Incident response scoping and impact assessment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#VPN anomaly#incident response#credential compromise#remote access

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice