🔥 3-day streak
Cisco CCNP Security SCOR (350-701)120 / 146
Question 120 of 146

During an active incident, threat intelligence confirms that a legitimately signed but abused remote-access tool (a portable .exe running from user profile directories) is being used by attackers for lateral movement across Windows endpoints managed by Cisco Secure Endpoint. The security team must immediately stop this specific executable from launching on all endpoints, but antivirus engines do not flag it as malicious because it is a valid application. Which outbreak control mechanism should the team use?

Reviewed for accuracy · Report an issueNext question