350-701 · Question #698
A network administrator has installed Secure Endpoint in the network. During setup it was noticed an endpoint has been exhibiting unusual behavior, including slow performance and unexpected network…
The correct answer is A. Isolate the endpoint from the network. When an endpoint exhibits unusual behavior and a suspicious file is discovered, the immediate and most crucial step for a network administrator is to isolate the endpoint from the network to prevent malware spread and further damage.
Question
A network administrator has installed Secure Endpoint in the network. During setup it was noticed an endpoint has been exhibiting unusual behavior, including slow performance and unexpected network activity. Administrator discovers a suspicious file named abc0467145535.exe running in the background. Which step must the network administrator take to investigate and remediate the potential malware?
Options
- AIsolate the endpoint from the network.
- BReset the endpoint password and enable multi-factor authentication.
- CFormat and reinstall the operating system on the endpoint.
- DDisable all non-essential processes running on the endpoint.
How the community answered
(28 responses)- A79% (22)
- B4% (1)
- C11% (3)
- D7% (2)
Why each option
When an endpoint exhibits unusual behavior and a suspicious file is discovered, the immediate and most crucial step for a network administrator is to isolate the endpoint from the network to prevent malware spread and further damage.
Isolating the endpoint from the network is the most critical immediate step in incident response to contain a potential malware infection, preventing it from spreading to other systems, exfiltrating data, or communicating with command-and-control servers.
Resetting passwords and enabling MFA are important security hygiene practices but do not directly address or contain an active malware infection running on the endpoint.
Formatting and reinstalling the operating system is a destructive remediation step that should typically occur *after* isolation and thorough investigation, not as the immediate first action.
Disabling non-essential processes might be part of a remediation plan, but it's less comprehensive and effective than network isolation for containing an unknown or active malware threat.
Concept tested: Incident Response: Endpoint Isolation
Source: https://docs.endpoint.security.cisco.com/en/latest/admin/threats/quarantine_endpoints.html
Topics
Community Discussion
No community discussion yet for this question.