Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam 200-201 All Questions
Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Cisco CyberOps Associate 200-201 Question # 56 Topic 6 Discussion

200-201 Exam Topic 6 Question 56 Discussion:
Question #: 56
Topic #: 6

The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling this event?


A.

Isolate the infected endpoint from the network.


B.

Perform forensics analysis on the infected endpoint.


C.

Collect public information on the malware behavior.


D.

Prioritize incident handling based on the impact.


Get Premium 200-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.