ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 169 - CS0-003 discussion

Report
Export

A security analyst detects an email server that had been compromised in the internal network. Users have been reporting strange messages in their email inboxes and unusual network traffic. Which of the following incident response steps should be performed next?

A.
Preparation
Answers
A.
Preparation
B.
Validation
Answers
B.
Validation
C.
Containment
Answers
C.
Containment
D.
Eradication
Answers
D.
Eradication
Suggested answer: C

Explanation:

After detecting a compromised email server and unusual network traffic, the next step in incident response is containment, to prevent further damage or spread of the compromise.Reference:CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 5: Incident Response, page 197.

asked 02/10/2024
Mohammad Sameer
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first