ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 301 - CAS-004 discussion

Report
Export

A host on a company's network has been infected by a worm that appears to be spreading via SMB. A security analyst has been tasked with containing the incident while also maintaining evidence for a subsequent investigation and malware analysis.

Which of the following steps would be best to perform FIRST?

A.
Turn off the infected host immediately.
Answers
A.
Turn off the infected host immediately.
B.
Run a full anti-malware scan on the infected host.
Answers
B.
Run a full anti-malware scan on the infected host.
C.
Modify the smb.conf file of the host to prevent outgoing SMB connections.
Answers
C.
Modify the smb.conf file of the host to prevent outgoing SMB connections.
D.
Isolate the infected host from the network by removing all network connections.
Answers
D.
Isolate the infected host from the network by removing all network connections.
Suggested answer: D
asked 02/10/2024
Jaimie Korik-Read
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first