mediumMultiple ChoiceObjective-mapped
200-201 A cybersecurity analyst in a SOC Practice Question
You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?
⚠ Common exam trap
Cisco often tests the principle that user reports of 'no unusual behavior' are unreliable in incident response, and that immediate containment (isolation) takes precedence over monitoring or partial blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network and perform a forensic analysis
The alert indicates a potential man-in-the-middle (MITM) attack or malware using a self-signed SSL certificate impersonating google.com. Isolating the workstation is critical to prevent lateral movement or data exfiltration while preserving evidence for forensic analysis. The combination of Snort NIDS detecting the malicious certificate and the connection to an unknown IP (192.0.2.10) strongly suggests compromise, regardless of user reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the alert because the user is unaware of any issue
Why it's wrong here
The user may not be aware of malware; the technical indicators are strong evidence of compromise.
- ✓
Isolate the workstation from the network and perform a forensic analysis
Why this is correct
Isolating the workstation prevents further damage, and forensic analysis can determine the root cause and scope of compromise.
- ✗
Wait and monitor the workstation for further alerts before taking action
Why it's wrong here
Delaying action could allow the attacker to steal data or move laterally.
- ✗
Block the destination IP 192.0.2.10 on the firewall
Why it's wrong here
Blocking the IP is a temporary measure, but the workstation may already be compromised; isolation is more comprehensive.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.