Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: A company's endpoint detection and response (EDR)…

A company's endpoint detection and response (EDR) agent is reporting a file that was created with a name matching a known ransomware pattern. The analyst suspects the file is malicious. What is the best first step to contain the threat?

⚠ Common exam trap

Cisco often tests the principle of 'containment before eradication' — the trap here is that candidates choose to delete the file or run a scan, thinking that removing the artifact stops the threat, but they overlook that the ransomware may already be executing in memory or have established persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the host from the network

Isolating the host from the network is the best first step because it immediately stops the ransomware from communicating with its command-and-control (C2) server and prevents lateral movement to other systems. The EDR agent has already flagged the file as suspicious, so the priority is containment, not further analysis or deletion, which could trigger the ransomware to encrypt data. Network isolation breaks the attack chain at the host level, buying time for forensic analysis and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a new firewall rule

    Why it's wrong here

    Firewall rules may help but isolation is more immediate and comprehensive.

  • Isolate the host from the network

    Why this is correct

    Isolation prevents lateral movement and C2 communication.

  • Run a full antivirus scan

    Why it's wrong here

    Scanning may take time and does not prevent network propagation.

  • Delete the file

    Why it's wrong here

    Deleting the file does not stop running processes or network spread.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.