Courseiva
easyMultiple ChoiceObjective-mapped

200-201 A security analyst at a medium-sized company Practice Question

You are a security analyst at a medium-sized company. A user reports that their workstation is running slowly and the network is sluggish. You check the firewall logs and see a large number of outgoing connections from the user's workstation to an external IP address (198.51.100.23) on port 4444. The connections are short-lived and occur every few seconds. The workstation has standard corporate antivirus installed, which is up-to-date and shows no threats. You have also noticed that the workstation is making DNS queries to an unusual domain (malicious.example.com) that resolves to the same external IP. What is the most appropriate immediate action?

⚠ Common exam trap

Cisco often tests the principle that containment (isolation) must precede analysis or remediation when active C2 traffic is observed, and the trap here is that candidates may choose to block the IP or run a scan, mistakenly thinking those actions are sufficient to stop the threat without removing the host from the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation by disconnecting it from the network immediately.

The workstation exhibits classic signs of a command-and-control (C2) infection: periodic outbound connections to an external IP on a non-standard port (4444) and DNS queries to a suspicious domain. Isolating the workstation immediately (Option B) is the most appropriate action because it stops the potential data exfiltration and prevents the malware from receiving further commands, containing the threat before any analysis or remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the external IP address on the firewall and continue monitoring.

    Why it's wrong here

    Blocking IP alone may not stop the malware from using other IPs.

  • Isolate the workstation by disconnecting it from the network immediately.

    Why this is correct

    Isolation stops C2 communication and preserves evidence.

  • Run a full forensic analysis on the workstation without disconnecting it.

    Why it's wrong here

    Running forensic analysis while connected risks further damage.

  • Update the antivirus signatures and run a full scan on the workstation.

    Why it's wrong here

    Antivirus may not detect custom malware; isolation is needed first.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.