List of questions
Related questions
Question 236 - CS0-003 discussion
An attacker recently gained unauthorized access to a financial institution's database, which contains confidential information. The attacker exfiltrated a large amount of data before being detected and blocked. A security analyst needs to complete a root cause analysis to determine how the attacker was able to gain access. Which of the following should the analyst perform first?
A.
Document the incident and any findings related to the attack for future reference.
B.
Interview employees responsible for managing the affected systems.
C.
Review the log files that record all events related to client applications and user access.
D.
Identify the immediate actions that need to be taken to contain the incident and minimize damage.
Your answer:
0 comments
Sorted by
Leave a comment first