Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 350-201 Topic 10 Question 90 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 90
Topic #: 10
[All 350-201 Questions]

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service are

a. What are the next steps the engineer must take?

Show Suggested Answer Hide Answer
Suggested Answer: A, D

Contribute your Thoughts:

Jutta
20 hours ago
Calling the incident handling provider? That's like calling the plumber to fix your computer. I think the engineer should use their investigative skills and get to the bottom of this.
upvoted 0 times
...
Alonso
9 days ago
Accepting this as a false positive is a terrible idea! That's like ignoring a fire alarm just because it's the weekend. Who knows what kind of havoc could be happening on the network.
upvoted 0 times
...
Keith
12 days ago
Option C seems like the most thorough approach. Defining the access points and understanding the services being offered during those hours will help pinpoint the root cause.
upvoted 0 times
...
Hildred
16 days ago
I believe defining the access points using StealthWatch or SIEM logs is crucial to understand the services being offered during that time.
upvoted 0 times
...
In
20 days ago
I agree with Nobuko. Blocking all traffic and documenting the results is a good next step.
upvoted 0 times
...
Bobbye
22 days ago
The engineer should definitely investigate this further. Blocking all traffic without understanding the issue could disrupt legitimate business operations.
upvoted 0 times
...
Nobuko
28 days ago
I think the engineer should review the SIEM and FirePower logs.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77