List of questions
Related questions
Question 257 - CAS-004 discussion
An analyst received a list of IOCs from a government agency. The attack has the following characteristics:
1- The attack starts with bulk phishing.
2- If a user clicks on the link, a dropper is downloaded to the computer.
3- Each of the malware samples has unique hashes tied to the user.
The analyst needs to identify whether existing endpoint controls are effective. Which of the following risk mitigation techniques should the analyst use?
A.
Update the incident response plan.
B.
Blocklist the executable.
C.
Deploy a honeypot onto the laptops.
D.
Detonate in a sandbox.
Your answer:
0 comments
Sorted by
Leave a comment first