700-270 · Question #26
Which security technique should be implemented to remediate after a threat is discovered?
The correct answer is C. retrospection. Retrospection is correct because it is specifically designed as a post-discovery technique - it allows security teams to look backward through historical data and file activity to understand how a threat behaved, what it touched, and what remediation steps are needed. This is esp
Question
Which security technique should be implemented to remediate after a threat is discovered?
Options
- Aapplication control
- Bweb security deployment
- Cretrospection
- DNGIPS ruleset
How the community answered
(58 responses)- A7% (4)
- B16% (9)
- C72% (42)
- D5% (3)
Explanation
Retrospection is correct because it is specifically designed as a post-discovery technique - it allows security teams to look backward through historical data and file activity to understand how a threat behaved, what it touched, and what remediation steps are needed. This is especially prominent in Cisco's security portfolio (e.g., AMP for Endpoints), where retrospective analysis re-evaluates previously seen files after new threat intelligence emerges.
Why the distractors are wrong:
- A. Application control - A preventive measure that restricts which applications can execute; it stops threats before they run, not after discovery.
- B. Web security deployment - A proactive/protective measure (web proxies, URL filtering) that blocks web-based threats; it is not a remediation technique triggered by threat discovery.
- D. NGIPS ruleset - Next-Generation IPS rules detect and block threats in real time during transit; they act before or during an attack, not after one has already been identified.
Memory tip: Think "retro = looking back." Retrospection is what you do after the fact - you go back in time through logs and file telemetry to understand and clean up a threat. If the question mentions "after a threat is discovered," that's your signal to pick the "looking back" answer.
Topics
Community Discussion
No community discussion yet for this question.