mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: A company's endpoint detection and response (EDR)…
A company's endpoint detection and response (EDR) agent is reporting a file that was created with a name matching a known ransomware pattern. The analyst suspects the file is malicious. What is the best first step to contain the threat?
⚠ Common exam trap
Cisco often tests the principle of 'containment before eradication' — the trap here is that candidates choose to delete the file or run a scan, thinking that removing the artifact stops the threat, but they overlook that the ransomware may already be executing in memory or have established persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the host from the network
Isolating the host from the network is the best first step because it immediately stops the ransomware from communicating with its command-and-control (C2) server and prevents lateral movement to other systems. The EDR agent has already flagged the file as suspicious, so the priority is containment, not further analysis or deletion, which could trigger the ransomware to encrypt data. Network isolation breaks the attack chain at the host level, buying time for forensic analysis and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new firewall rule
Why it's wrong here
Firewall rules may help but isolation is more immediate and comprehensive.
- ✓
Isolate the host from the network
Why this is correct
Isolation prevents lateral movement and C2 communication.
- ✗
Run a full antivirus scan
Why it's wrong here
Scanning may take time and does not prevent network propagation.
- ✗
Delete the file
Why it's wrong here
Deleting the file does not stop running processes or network spread.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.