Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 A cybersecurity analyst in a SOC Practice Question

You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?

⚠ Common exam trap

Cisco often tests the principle that user reports of 'no unusual behavior' are unreliable in incident response, and that immediate containment (isolation) takes precedence over monitoring or partial blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation from the network and perform a forensic analysis

The alert indicates a potential man-in-the-middle (MITM) attack or malware using a self-signed SSL certificate impersonating google.com. Isolating the workstation is critical to prevent lateral movement or data exfiltration while preserving evidence for forensic analysis. The combination of Snort NIDS detecting the malicious certificate and the connection to an unknown IP (192.0.2.10) strongly suggests compromise, regardless of user reports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ignore the alert because the user is unaware of any issue

    Why it's wrong here

    The user may not be aware of malware; the technical indicators are strong evidence of compromise.

  • Isolate the workstation from the network and perform a forensic analysis

    Why this is correct

    Isolating the workstation prevents further damage, and forensic analysis can determine the root cause and scope of compromise.

  • Wait and monitor the workstation for further alerts before taking action

    Why it's wrong here

    Delaying action could allow the attacker to steal data or move laterally.

  • Block the destination IP 192.0.2.10 on the firewall

    Why it's wrong here

    Blocking the IP is a temporary measure, but the workstation may already be compromised; isolation is more comprehensive.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.