List of questions
Related questions
Question 338 - CS0-003 discussion
A report contains IoC and TTP information for a zero-day exploit that leverages vulnerabilities in a specific version of a web application. Which of the following actions should a SOC analyst take first after receiving the report?
A.
Implement a vulnerability scan to determine whether the environment is at risk.
B.
Block the IP addresses and domains from the report in the web proxy and firewalls.
C.
Verify whether the information is relevant to the organization.
D.
Analyze the web application logs to identify any suspicious or malicious activity.
Your answer:
0 comments
Sorted by
Leave a comment first