ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 141 - CAS-004 discussion

Report
Export

A security analyst observes the following while looking through network traffic in a company's cloud log:

Which of the following steps should the security analyst take FIRST?

A.
Quarantine 10.0.5.52 and run a malware scan against the host.
Answers
A.
Quarantine 10.0.5.52 and run a malware scan against the host.
B.
Access 10.0.5.52 via EDR and identify processes that have network connections.
Answers
B.
Access 10.0.5.52 via EDR and identify processes that have network connections.
C.
Isolate 10.0.50.6 via security groups.
Answers
C.
Isolate 10.0.50.6 via security groups.
D.
Investigate web logs on 10.0.50.6 to determine if this is normal traffic.
Answers
D.
Investigate web logs on 10.0.50.6 to determine if this is normal traffic.
Suggested answer: D
asked 02/10/2024
Harshvir Bhati
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first