
CCIE Security
Domain 5Objective 2
5.2 Detect, Analyze, and Mitigate Malware Incidents CCIE-SECURITY Practice Questions (Page 10)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
20%of the exam
Questions 46–50
- 46
A hospital's IT team discovers ransomware on a few workstations in the cardiology department. The ransomware appears to be spreading laterally. The team must respond while ensuring patient care is not disrupted. What should be the FIRST step in the incident response process?
Select an answer first - 47
A security team is integrating threat intelligence feeds into their SIEM. They receive a high volume of alerts from the feed, many of which are false positives. The team wants to reduce noise while maintaining detection of real threats. Which approach is most effective?
Select an answer first - 48
A malware analyst receives a suspicious executable from a compromised host. The analyst needs to quickly determine if the binary is packed and identify its imports without executing it. Which analysis method should be used?
Select an answer first - 49
A company has experienced multiple malware infections originating from the marketing department's shared drive. The infections spread to other departments via SMB shares. The security team wants to reduce the impact of future malware incidents. Which mitigation strategy is most effective?
Select an answer first - 50
A security operations center (SOC) is overwhelmed by alerts from a new malware campaign. The malware uses dynamic DNS and frequently changes its command-and-control (C2) domains. The SOC wants to improve detection while reducing false positives. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.