List of questions
Related questions
Question 363 - CAS-004 discussion
A company recently deployed a SIEM and began importing logs from a firewall, a file server, a domain controller a web server, and a laptop. A security analyst receives a series of SIEM alerts and prepares to respond. The following is the alert information:
Which of the following should the security analyst do FIRST?
A.
Disable Administrator on abc-uaa-fsl, the local account is compromised
B.
Shut down the abc-usa-fsl server, a plaintext credential is being used
C.
Disable the jdoe account, it is likely compromised
D.
Shut down abc-usa-fw01; the remote access VPN vulnerability is exploited
Your answer:
0 comments
Sorted by
Leave a comment first