mediumMultiple Choice
200-201 A cybersecurity analyst in a SOC Practice Question
You are a cybersecurity analyst in a SOC. The company uses a combination of Snort NIDS and Windows Event Log monitoring. At 3:00 PM, you receive a critical alert: 'ET TROJAN Observed Malicious SSL Certificate (Fake Google)'. The alert shows that a workstation (IP 10.0.1.45) initiated an SSL connection to IP 192.0.2.10 on port 443. The certificate presented by the server is self-signed and claims to be 'google.com'. The destination IP is not in any known Google IP range. You check the firewall logs and see that the outbound connection was allowed. The workstation's host logs show that the user is a marketing employee who frequently accesses webmail. The user reports no unusual behavior. You also check the company's web proxy logs and see that the user accessed 'http://www.google.com' earlier today, but the SSL connection is to a different IP. What should be your next step?
⚠ Common exam trap
Cisco often tests the principle that user reports of 'no unusual behavior' are unreliable in incident response, and that immediate containment (isolation) takes precedence over monitoring or partial blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network and perform a forensic analysis
The alert indicates a potential man-in-the-middle (MITM) attack or malware using a self-signed SSL certificate impersonating google.com. Isolating the workstation is critical to prevent lateral movement or data exfiltration while preserving evidence for forensic analysis. The combination of Snort NIDS detecting the malicious certificate and the connection to an unknown IP (192.0.2.10) strongly suggests compromise, regardless of user reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the alert because the user is unaware of any issue
Why it's wrong here
User unawareness carries no evidential weight; the self-signed certificate claiming google.com from a non-Google IP is a strong indicator of compromise requiring investigation. Ignoring it is tempting because benign browsing appears in proxy logs, but that traffic went to a different destination, so it does not explain this connection.
- ✓
Isolate the workstation from the network and perform a forensic analysis
Why this is correct
The self-signed certificate claiming google.com from a non-Google IP indicates likely command-and-control or credential theft, so isolating the host contains the threat before lateral movement. Forensic analysis then determines scope and persistence while preserving evidence.
- ✗
Wait and monitor the workstation for further alerts before taking action
Why it's wrong here
Monitoring delays containment while the workstation may already be beaconing to the rogue server; the fake certificate and non-Google destination constitute an active indicator requiring immediate investigation. Waiting is tempting to avoid disrupting a marketing employee's work, but passive observation forfeits the chance to contain exfiltration.
- ✗
Block the destination IP 192.0.2.10 on the firewall
Why it's wrong here
Blocking one destination IP is a point mitigation: the workstation remains compromised and can reach the attacker via other addresses or domains. It is tempting because firewall blocking is fast and low-risk, but the correct response isolates the host and investigates before remediating the specific indicator.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.