Refer to the exhibit. An analyst sees repeated denied TCP connections from the same source to the same destination web server. Which of the following actions should the analyst take first?
Repeated denied TCP connections from one source to one web server suggest scanning or brute-force activity. Investigating the source IP establishes whether it is an internal compromised host or external attacker, guiding the appropriate containment response.
Why this answer
Repeated denied TCP connections from the same source to the same destination web server are a classic indicator of a potential reconnaissance or attack pattern, such as a port scan or brute-force attempt. The first priority in security monitoring is to investigate the source IP for malicious activity (Option C) to determine intent and scope before taking any irreversible action. This aligns with the incident response process of identification and analysis before containment or eradication.
Exam trap
Cisco often tests the candidate's understanding of the incident response order of operations, where the trap is to jump to a containment action (like blocking or permitting) without first performing analysis and validation of the threat.
How to eliminate wrong answers
Option A is wrong because increasing the logging level may provide more detail but does not address the immediate need to determine if the source IP is malicious; it delays the investigative step and could overwhelm the analyst with noise. Option B is wrong because creating a permit rule for the source IP would allow all traffic from that IP, which could enable an attacker to bypass security controls if the source is indeed malicious; this action should only be taken after confirming the source is legitimate. Option D is wrong because blocking the source IP globally is a premature containment action that could disrupt legitimate business operations if the source is a false positive; it should only be performed after investigation confirms malicious intent.