ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 207 - CS0-003 discussion

Report
Export

During an incident, some loCs of possible ransomware contamination were found in a group of servers in a segment of the network. Which of the following steps should be taken next?

A.
Isolation
Answers
A.
Isolation
B.
Remediation
Answers
B.
Remediation
C.
Reimaging
Answers
C.
Reimaging
D.
Preservation
Answers
D.
Preservation
Suggested answer: A

Explanation:

Isolation is the first step to take after detecting some indicators of compromise (IoCs) of possible ransomware contamination. Isolation prevents the ransomware from spreading to other servers or segments of the network, and allows the security team to investigate and contain the incident. Isolation can be done by disconnecting the infected servers from the network, blocking the malicious traffic, or applying firewall rules12.

asked 02/10/2024
John Doe
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first