easyMultiple Choice
200-201 A security analyst at a medium-sized company Practice Question
You are a security analyst at a medium-sized company. A user reports that their workstation is running slowly and the network is sluggish. You check the firewall logs and see a large number of outgoing connections from the user's workstation to an external IP address (198.51.100.23) on port 4444. The connections are short-lived and occur every few seconds. The workstation has standard corporate antivirus installed, which is up-to-date and shows no threats. You have also noticed that the workstation is making DNS queries to an unusual domain (malicious.example.com) that resolves to the same external IP. What is the most appropriate immediate action?
⚠ Common exam trap
Cisco often tests the principle that containment (isolation) must precede analysis or remediation when active C2 traffic is observed, and the trap here is that candidates may choose to block the IP or run a scan, mistakenly thinking those actions are sufficient to stop the threat without removing the host from the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation by disconnecting it from the network immediately.
The workstation exhibits classic signs of a command-and-control (C2) infection: periodic outbound connections to an external IP on a non-standard port (4444) and DNS queries to a suspicious domain. Isolating the workstation immediately (Option B) is the most appropriate action because it stops the potential data exfiltration and prevents the malware from receiving further commands, containing the threat before any analysis or remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the external IP address on the firewall and continue monitoring.
Why it's wrong here
Blocking only the single external IP leaves the infected host beaconing and the malware resident; the attacker can simply rotate to another address or domain. Firewall blocking suits known indicators, but the immediate priority is isolating the compromised workstation itself.
- ✓
Isolate the workstation by disconnecting it from the network immediately.
Why this is correct
Beaconing to port 4444 every few seconds, with DNS resolving to the same external IP, indicates active command-and-control traffic that antivirus missed. Disconnecting the workstation immediately severs that channel, preventing data exfiltration or further instruction while preserving volatile evidence for later forensic analysis.
- ✗
Run a full forensic analysis on the workstation without disconnecting it.
Why it's wrong here
Leaving the workstation connected lets the implant keep beaconing to 198.51.100.23 every few seconds, exfiltrating data and enabling remote commands during analysis. Forensic imaging is appropriate later, after containment, not as the immediate response to active command-and-control traffic.
- ✗
Update the antivirus signatures and run a full scan on the workstation.
Why it's wrong here
The antivirus is already current and reports no threats, so signature updates and another scan cannot detect this implant; the beaconing continues meanwhile. Scanning suits known-malware detection, but here containment of the confirmed command-and-control channel must come first.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.