hardMultiple SelectObjective-mapped
200-201 Practice Question: An analyst is investigating a host that is…
An analyst is investigating a host that is suspected of being compromised. The host's security logs show multiple failed login attempts followed by a successful login from an unusual IP address, and then a series of outbound connections to known malicious destinations. Which TWO actions should the analyst take immediately? (Choose two.)
⚠ Common exam trap
Cisco often tests the misconception that immediate remediation (deleting files, running antivirus) is the priority, when in fact containment (isolation) and evidence preservation (forensic imaging) are the correct first steps in a structured incident response process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the host from the network
Isolating the host from the network immediately stops the outbound connections to known malicious destinations, preventing further data exfiltration, lateral movement, or command-and-control (C2) communication. This containment step is critical in incident response to limit the blast radius before any other investigative or remediation actions are taken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the malicious files found on the host
Why it's wrong here
Deleting files destroys evidence; preservation is critical.
- ✓
Isolate the host from the network
Why this is correct
Isolating the host stops ongoing malicious activity and prevents lateral movement.
- ✓
Collect a forensic image of the host's hard drive
Why this is correct
A forensic image preserves volatile and non-volatile evidence for detailed analysis.
- ✗
Reboot the host to clear any malware from memory
Why it's wrong here
Rebooting destroys volatile evidence and may allow malware to persist.
- ✗
Run a full antivirus scan on the host
Why it's wrong here
Running a scan may alter evidence and is not the immediate priority.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.