Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam 350-201 All Questions
Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Cisco CyberOps Professional 350-201 Question # 40 Topic 5 Discussion

350-201 Exam Topic 5 Question 40 Discussion:
Question #: 40
Topic #: 5

A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user’s laptop while traveling. The attacker has the user’s credentials and is attempting to connect to the network.

What is the next step in handling the incident?


A.

Block the source IP from the firewall


B.

Perform an antivirus scan on the laptop


C.

Identify systems or services at risk


D.

Identify lateral movement


Get Premium 350-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.