Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right.

A SOC engineer discovers that the organization had three DDOS attacks overnight. Four servers are reported offline, even though the hardware seems to be working as expected. One of the offline servers is affecting the pay system reporting times. Three employees, including executive management, have reported ransomware on their laptops. Which steps help the engineer understand a comprehensive overview of the incident?

A.

Run and evaluate a full packet capture on the workloads, review SIEM logs, and define a root cause.

B.

Run and evaluate a full packet capture on the workloads, review SIEM logs, and plan mitigation steps.

C.

Check SOAR to learn what the security systems are reporting about the overnight events, research the attacks, and plan mitigation step.

D.

Check SOAR to know what the security systems are reporting about the overnight events, review the threat vectors, and define a root cause.

According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?

A.

Perform a vulnerability assessment

B.

Conduct a data protection impact assessment

C.

Conduct penetration testing

D.

Perform awareness testing

A malware outbreak is detected by the SIEM and is confirmed as a true positive. The incident response team follows the playbook to mitigate the threat. What is the first action for the incident response team?

A.

Assess the network for unexpected behavior

B.

Isolate critical hosts from the network

C.

Patch detected vulnerabilities from critical hosts

D.

Perform analysis based on the established risk factors

Refer to the exhibit.

Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?

A.

NetFlow and event data

B.

event data and syslog data

C.

SNMP and syslog data

D.

NetFlow and SNMP

An organization lost connectivity to critical servers, and users cannot access business applications and internal websites. An engineer checks the network devices to investigate the outage and determines that all devices are functioning. Drag and drop the steps from the left into the sequence on the right to continue investigating this issue. Not all options are used.

Refer to the exhibit.

What results from this script?

A.

Seeds for existing domains are checked

B.

A search is conducted for additional seeds

C.

Domains are compared to seed rules

D.

A list of domains as seeds is blocked

An engineer returned to work and realized that payments that were received over the weekend were sent to the wrong recipient. The engineer discovered that the SaaS tool that processes these payments was down over the weekend. Which step should the engineer take first?

A.

Utilize the SaaS tool team to gather more information on the potential breach

B.

Contact the incident response team to inform them of a potential breach

C.

Organize a meeting to discuss the services that may be affected

D.

Request that the purchasing department creates and sends the payments manually

Drag and drop the mitigation steps from the left onto the vulnerabilities they mitigate on the right.

Refer to the exhibit.

Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a quarantine VLAN using Adaptive Network Control policy. Which method was used to signal ISE to quarantine the endpoints?

A.

SNMP

B.

syslog

C.

REST API

D.

pxGrid