Performing CyberOps Using Cisco Security Technologies (CBRCOR) — Question 79

An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?

Answer options

Correct answer: A

Explanation

The correct answer is A because it is a pragmatic approach to involve the incident handling provider when no issues are detected during business hours, implying a potential non-business related activity. Option B suggests blocking all traffic, which could disrupt legitimate services, while C focuses on technical analysis rather than immediate response. Option D dismisses the activity without investigation, which is not advisable.