Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?

⚠ Common exam trap

The trap here is treating the report as a suggestion rather than actionable intelligence, leading to delayed containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the domain at the DNS layer and investigate any internal hosts that queried it

A domain flagged as malware and command-and-control with a high security score should be blocked immediately to sever communication. The analyst must also identify internal hosts that resolved the domain to determine the scope of compromise. This two-step approach of containment and investigation is the correct first response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the domain to a watchlist and continue monitoring for 24 hours

    Why it's wrong here

    Adding to a watchlist and waiting allows potential command-and-control traffic to continue, risking data exfiltration or further compromise. The domain is already confirmed malicious by multiple categories, so immediate action is warranted. Monitoring alone is insufficient when active C2 communication is suspected; containment should not be delayed.

  • ✗

    Submit the domain to Cisco Talos for reclassification

    Why it's wrong here

    Submitting for reclassification is appropriate when a domain is wrongly categorized, but here multiple malicious categories and a high security score confirm the verdict. Reclassification would not address the immediate threat. The analyst should act on the intelligence rather than question it, unless there is strong evidence of a false positive.

  • ✓

    Block the domain at the DNS layer and investigate any internal hosts that queried it

    Why this is correct

    When a domain is categorized as malware and command-and-control with a high security score, the immediate priority is to prevent further communication and identify affected hosts. Blocking at DNS via Umbrella stops resolution, and querying logs for internal clients that resolved the domain helps scope the incident. This aligns with containment and investigation best practices.

  • ✗

    Report the domain to the ISP and wait for their response

    Why it's wrong here

    Reporting to an ISP is a slow process and does not protect the internal network. The analyst has the authority and tools to block the domain locally via Umbrella. Waiting for an external party to act leaves the organization exposed to ongoing C2 traffic and potential data theft.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.