ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 5 - CS0-003 discussion

Report
Export

During an extended holiday break, a company suffered a security incident. This information was properly relayed to appropriate personnel in a timely manner and the server was up to date and configured with appropriate auditing and logging. The Chief Information Security Officer wants to find out precisely what happened. Which of the following actions should the analyst take first?

A.
Clone the virtual server for forensic analysis
Answers
A.
Clone the virtual server for forensic analysis
B.
Log in to the affected server and begin analysis of the logs
Answers
B.
Log in to the affected server and begin analysis of the logs
C.
Restore from the last known-good backup to confirm there was no loss of connectivity
Answers
C.
Restore from the last known-good backup to confirm there was no loss of connectivity
D.
Shut down the affected server immediately
Answers
D.
Shut down the affected server immediately
Suggested answer: A

Explanation:

The first action that the analyst should take in this case is to clone the virtual server for forensic analysis. Cloning the virtual server involves creating an exact copy or image of the server's data and state at a specific point in time. Cloning the virtual server can help preserve and protect any evidence or information related to the security incident, as well as prevent any tampering, contamination, or destruction of evidence. Cloning the virtual server can also allow the analyst to safely analyze and investigate the incident without affecting the original server or its operations.

asked 02/10/2024
Kefash White
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first