🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)58 / 147
Question 58 of 147
A SOC analyst receives an alert that a networked smart thermostat (an embedded Linux IoT device) in a corporate facility is beaconing to an unfamiliar external IP over an encrypted channel. The device has no traditional EDR agent, limited storage, and a read-only firmware partition. The analyst must begin investigating the potential endpoint intrusion. Given the platform constraints, what is the MOST appropriate first investigative step?
Reviewed for accuracy · Report an issueNext question