List of questions
Related questions
Question 266 - 200-201 discussion
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)
A.
Isolate affected endpoints and take disk images for analysis
B.
Provide security awareness training to HR managers and employees
C.
Block connection to this C&C server on the perimeter next-generation firewall
D.
Update antivirus signature databases on affected endpoints to block connections to C&C
E.
Detect the attack vector and analyze C&C connections
Your answer:
0 comments
Sorted by
Leave a comment first