nerdexam
Cisco

700-270 · Question #26

Which security technique should be implemented to remediate after a threat is discovered?

The correct answer is C. retrospection. Retrospection is correct because it is specifically designed as a post-discovery technique - it allows security teams to look backward through historical data and file activity to understand how a threat behaved, what it touched, and what remediation steps are needed. This is esp

Understanding Next-Generation Firewall Technology and Concepts

Question

Which security technique should be implemented to remediate after a threat is discovered?

Options

  • Aapplication control
  • Bweb security deployment
  • Cretrospection
  • DNGIPS ruleset

How the community answered

(58 responses)
  • A
    7% (4)
  • B
    16% (9)
  • C
    72% (42)
  • D
    5% (3)

Explanation

Retrospection is correct because it is specifically designed as a post-discovery technique - it allows security teams to look backward through historical data and file activity to understand how a threat behaved, what it touched, and what remediation steps are needed. This is especially prominent in Cisco's security portfolio (e.g., AMP for Endpoints), where retrospective analysis re-evaluates previously seen files after new threat intelligence emerges.

Why the distractors are wrong:

  • A. Application control - A preventive measure that restricts which applications can execute; it stops threats before they run, not after discovery.
  • B. Web security deployment - A proactive/protective measure (web proxies, URL filtering) that blocks web-based threats; it is not a remediation technique triggered by threat discovery.
  • D. NGIPS ruleset - Next-Generation IPS rules detect and block threats in real time during transit; they act before or during an attack, not after one has already been identified.

Memory tip: Think "retro = looking back." Retrospection is what you do after the fact - you go back in time through logs and file telemetry to understand and clean up a threat. If the question mentions "after a threat is discovered," that's your signal to pick the "looking back" answer.

Topics

#Threat Remediation#Incident Response#Post-Incident Analysis#Security Operations

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice