ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 176 - CS0-003 discussion

Report
Export

A cybersecurity analyst has recovered a recently compromised server to its previous state. Which of the following should the analyst perform next?

A.
Eradication
Answers
A.
Eradication
B.
Isolation
Answers
B.
Isolation
C.
Reporting
Answers
C.
Reporting
D.
Forensic analysis
Answers
D.
Forensic analysis
Suggested answer: D

Explanation:

After recovering a compromised server to its previous state, the analyst should perform forensic analysis to determine the root cause, impact, and scope of the incident, as well as to identify any indicators of compromise, evidence, or artifacts that can be used for further investigation or prosecution.

Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 6, page 244; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 6, page 253.

asked 02/10/2024
Raja Tarazi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first