mediumMultiple Choice
200-201 Practice Question: A security analyst at a medium-sized enterprise…
A security analyst at a medium-sized enterprise notices that an employee's workstation has been sending outbound traffic to a known malicious IP address at irregular intervals. The analyst runs a scan and finds no malware signatures. What should the analyst do next?
⚠ Common exam trap
The trap is choosing an immediate disruptive action (block, disconnect, reimage) that feels decisive but destroys evidence or is premature, instead of escalating for proper investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate to the incident response team for further investigation.
Outbound traffic to a known malicious IP with no matching malware signature indicates a potential compromise that evaded signature-based detection — likely a fileless, living-off-the-land, or encrypted C2 channel. The correct next step is to escalate to the incident response team so they can perform deeper analysis (memory forensics, network capture, threat hunting) before taking disruptive action. Escalation preserves evidence and follows the incident response process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the malicious IP at the firewall and continue monitoring.
Why it's wrong here
Blocking the IP at the firewall stops that destination but leaves the workstation compromised and beaconing to alternate command-and-control infrastructure. It is tempting because it is fast, low-disruption containment, and would be correct as a temporary measure alongside endpoint investigation, not as the next analytical step.
- ✓
Escalate to the incident response team for further investigation.
Why this is correct
Absent malware signatures, the irregular beaconing to a known malicious IP still indicates possible command-and-control or compromised credentials. Escalating to the incident response team brings deeper forensic analysis, such as traffic inspection and endpoint telemetry review, which signature scanning alone cannot provide.
- ✗
Review the employee's recent web browsing history and email attachments.
Why it's wrong here
Browsing history and email attachments are reviewed after identifying the delivery vector, but they do not reveal the active process generating the beaconing traffic. It is tempting because phishing is a common initial access route, and this review would be correct once the malicious process or persistence mechanism is scoped.
- ✗
Immediately disconnect the workstation from the network and reimage it.
Why it's wrong here
Reimaging destroys volatile evidence such as memory-resident malware and network artefacts before the beaconing is understood, and no signature was found to justify it. It is tempting because reimaging guarantees removal of any compromise, and would be correct once malware is confirmed and contained.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.