nerdexam
Cisco

350-201 · Question #70

The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all…

The correct answer is B. Isolate the infected host from the rest of the subnet. Short-term containment - limiting damage before the incident gets worse, usually by isolating network segments, taking down hacked production server and routing to failover.

Processes

Question

The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all the necessary evidence from the computing resource. What is the next step?

Options

  • AConduct a risk assessment of systems and applications
  • BIsolate the infected host from the rest of the subnet
  • CInstall malware prevention software on the host
  • DAnalyze network traffic on the host's subnet

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    91% (20)
  • D
    5% (1)

Explanation

Short-term containment - limiting damage before the incident gets worse, usually by isolating network segments, taking down hacked production server and routing to failover.

Topics

#incident response#containment#malware#USB threat

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice