200-201 Security Monitoring Practice Question
A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?
⚠ Common exam trap
The trap here is assuming that blocking the external IPs or the port immediately resolves the incident, when the real issue is the potentially compromised internal host that must be investigated first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the workstation for signs of compromise and determine whether it is running an unauthorized RDP service.
Inbound RDP traffic to a workstation from multiple external sources is a strong indicator that the host may be compromised and running an unauthorized remote access service. The correct first step is to investigate the endpoint to confirm the compromise and gather evidence before taking containment actions. This aligns with the incident response process of identification and scoping before eradication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restart the workstation to terminate any active RDP sessions and clear potential malware from memory.
Why it's wrong here
Restarting the workstation destroys volatile evidence such as running processes, network connections, and in-memory malware artifacts. This action would hinder a proper forensic investigation and may allow the attacker to persist through other mechanisms. Containment should be deliberate and evidence-preserving, not a blind reboot.
- ✗
Block TCP port 3389 inbound on the perimeter firewall for all internal hosts.
Why it's wrong here
Blocking RDP inbound at the perimeter for all hosts is a broad, disruptive change that may interrupt legitimate remote administration and does not address the specific compromised workstation. The immediate priority is to investigate the anomalous host, not to apply a network-wide policy without understanding the scope or business impact of the change.
- ✓
Investigate the workstation for signs of compromise and determine whether it is running an unauthorized RDP service.
Why this is correct
A workstation receiving inbound RDP connections from multiple external IPs is highly suspicious because workstations should not expose RDP to the internet. The analyst should first investigate the endpoint to confirm whether an attacker has enabled RDP or installed a backdoor, gather evidence, and then contain the incident appropriately.
- ✗
Add the external IP addresses to the firewall blocklist and close the incident.
Why it's wrong here
Blocking the external IPs may provide temporary relief, but it does not address the compromised internal host, which could still initiate outbound connections or be controlled via other channels. Closing the incident without investigating the workstation leaves the root cause unresolved and the network at continued risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.