easyMultiple ChoiceObjective-mapped
Trojan IDS Alert Response — First Step Investigate Source Host
An analyst sees an alert from the IDS: 'ET TROJAN Possible Zeus Variant Outbound Connection'. What action should the analyst take first?
Quick Answer
The answer is to investigate the source host for signs of compromise. This is the correct first action because a Trojan IDS alert, such as one detecting a possible Zeus variant making an outbound connection, indicates potential command-and-control (C2) traffic; the analyst must validate the alert through host-based analysis—checking processes, registry entries, and active network connections—before taking any containment steps. On the Cisco CyberOps Associate 200-201 exam, this scenario tests your understanding of the incident response process, specifically the priority of verification over reaction. A common trap is jumping to block the IP address, but that can destroy evidence and fail against malware using domain flux. Remember the memory tip: “Verify before you modify”—always confirm compromise on the source host first to preserve forensic integrity and avoid disrupting the investigation.
⚠ Common exam trap
Cisco often tests the principle that IDS/IPS alerts require verification before action—candidates mistakenly choose to block or reimage immediately, but the correct first step is always to investigate the affected host to confirm the alert and preserve evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the source host for signs of compromise
The first priority when an IDS alerts on a possible Zeus variant (a known Trojan) is to investigate the source host to confirm or rule out compromise. Zeus is a credential-stealing Trojan that often establishes outbound C2 (command-and-control) traffic; blindly blocking the IP (A) could disrupt the investigation and may not stop the malware if it uses domain flux or multiple IPs. Reimaging (D) destroys forensic evidence, and ignoring the alert (B) is negligent given the severity of Zeus. The analyst must perform host-based analysis (e.g., check processes, registry, network connections) to validate the alert before taking containment actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the IP address on the firewall
Why it's wrong here
Blocking without investigation may block legitimate traffic.
- ✗
Ignore the alert as a false positive
Why it's wrong here
Ignoring could miss a real threat.
- ✓
Investigate the source host for signs of compromise
Why this is correct
Investigation confirms if the alert is valid.
- ✗
Reimage the host immediately
Why it's wrong here
Reimaging is drastic without confirmation.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-201
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst is reviewing a Snort alert that triggered on the signature 'ET TROJAN Win.Trojan.Generic'. What is the most likely reason this alert fired?
easy- ✓ A.A system infected with a trojan
- B.A legitimate Windows update
- C.A misconfigured firewall
- D.An attacker attempting to exploit a buffer overflow
Why A: The Snort signature 'ET TROJAN Win.Trojan.Generic' is designed to detect network traffic patterns or payloads associated with known Trojan malware. When this alert fires, it indicates that the sensor observed data matching the signature's characteristics, most likely from a system that is infected with a Trojan and is communicating with a command-and-control server or performing malicious activity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.